PT-2021-19501 · Typo3 · Media2Click
Alexander Sidukov
+4
·
Published
2021-04-28
·
Updated
2021-06-08
·
CVE-2021-31778
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
media2click (aka 2 Clicks for External Media) extension versions 1.x before 1.3.3 for TYPO3
Description
The issue allows for XSS by a backend user account.
Recommendations
For media2click (aka 2 Clicks for External Media) extension versions 1.x before 1.3.3, update to version 1.3.3 or later to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Media2Click