Cross-Site Scripting in Fluid view helpers
CVE-2020-26227
6.1MEDIUM
What is CVE-2020-26227?
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fluid) of the TYPO3 core is vulnerable to cross-site scripting passing user-controlled data as argument to Fluid view helpers. Update to TYPO3 versions 9.5.23 or 10.4.10 that fix the problem described.
Affected Version(s)
TYPO3.CMS >= 9.0.0, < 9.5.23 < 9.0.0, 9.5.23
TYPO3.CMS >= 10.0.0, < 10.4.10 < 10.0.0, 10.4.10
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved