XSS Vulnerability in TYPO3 cs_seo Extension
CVE-2025-48203

6.4MEDIUM

Key Information:

Vendor

Typo3

Vendor
CVE Published:
21 May 2025

What is CVE-2025-48203?

The cs_seo extension for TYPO3, versions up to 9.2.0, is susceptible to a Cross-Site Scripting (XSS) vulnerability. This security flaw can be exploited by an attacker to inject malicious scripts into web pages viewed by users, potentially compromising user sessions and sensitive information. It is crucial for TYPO3 site administrators to apply the latest patches and follow security best practices to mitigate this risk.

Affected Version(s)

cs seo extension 6.3.0 < 6.8.0

cs seo extension 7.0.0 < 7.5.0

cs seo extension 8.0.0 < 8.4.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
The Cyber Security Vulnerability Database.