PT-2021-3864 · Typo3 · Typo3

Oliver Bartsch

·

Published

2021-07-20

·

Updated

2024-03-06

·

CVE-2021-32667

CVSS v3.1

6.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 versions 9.0.0 through 9.5.28 TYPO3 versions 10.0.0 through 10.4.17 TYPO3 versions 11.0.0 through 11.3.0
Description The issue is related to the implementation of the Page TSconfig configuration in the TYPO3 content management system, which fails to properly encode settings, making the corresponding page preview module vulnerable to persistent cross-site scripting attacks. A valid backend user account is required to exploit this vulnerability.
Recommendations For versions 9.0.0 through 9.5.28, update to version 9.5.29. For versions 10.0.0 through 10.4.17, update to version 10.4.18. For versions 11.0.0 through 11.3.0, update to version 11.3.1.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04222
BIT-TYPO3-2021-32667
CVE-2021-32667
GHSA-8MQ9-FQV8-59WF

Affected Products

Typo3