PT-2021-14434 · Typo3 · Typo3

Richie Lee

·

Published

2021-03-23

·

Updated

2024-03-06

·

CVE-2021-21340

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 versions prior to 10.4.14 TYPO3 versions prior to 11.1.1
Description The issue concerns database fields used as descriptionColumn that are vulnerable to cross-site scripting when their content gets previewed. A valid backend user account is needed to exploit this issue.
Recommendations Update to version 10.4.14 to resolve the issue for versions prior to 10.4.14. Update to version 11.1.1 to resolve the issue for versions prior to 11.1.1.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-TYPO3-2021-21340
CVE-2021-21340
GHSA-FJH3-G8GQ-9Q92

Affected Products

Typo3