Cross-Site Scripting in Fluid view helpers
CVE-2020-26227

6.1MEDIUM

Key Information:

Vendor

Typo3

Status
Vendor
CVE Published:
23 November 2020

What is CVE-2020-26227?

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fluid) of the TYPO3 core is vulnerable to cross-site scripting passing user-controlled data as argument to Fluid view helpers. Update to TYPO3 versions 9.5.23 or 10.4.10 that fix the problem described.

Affected Version(s)

TYPO3.CMS >= 9.0.0, < 9.5.23 < 9.0.0, 9.5.23

TYPO3.CMS >= 10.0.0, < 10.4.10 < 10.0.0, 10.4.10

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.