PT-2020-12525 · Typo3 · Typo3/Cms

Florian Weiss

·

Published

2020-05-13

·

Updated

2024-03-06

·

CVE-2020-11064

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 CMS versions 9.0.0 through 9.5.16 TYPO3 CMS versions 10.0.0 through 10.4.1
Description A cross-site scripting issue has been discovered in the HTML placeholder attributes, which contain data from other database records. This issue can be exploited with a valid backend user account.
Recommendations For TYPO3 CMS versions 9.0.0 through 9.5.16, update to version 9.5.17. For TYPO3 CMS versions 10.0.0 through 10.4.1, update to version 10.4.2.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-TYPO3-2020-11064
CVE-2020-11064
GHSA-43GJ-MJ2W-WH46

Affected Products

Typo3/Cms