PT-2021-21361 · Typo3 · Typo3 Routes Extension

Oliver Hader

·

Published

2021-08-13

·

Updated

2022-07-12

·

CVE-2021-36793

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 routes extension versions prior to 2.1.1
Description The issue allows sensitive information disclosure because a session identifier is present in HTML output when CsrfTokenViewHelper is used. This occurs when the extension discloses the user's session identifier to HTML output without additional cryptographic hashing algorithms. The vulnerability cannot be exploited directly and requires a chained attack, such as Cross Site Scripting in the frontend output.
Recommendations For versions prior to 2.1.1, update to version 2.1.1 or later to resolve the issue. As a temporary workaround, consider disabling the CsrfTokenViewHelper until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation.

Fix

Information Disclosure

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36793
GHSA-VPW5-GRXX-V396

Affected Products

Typo3 Routes Extension