PT-2022-21714 · Typo3 · Typo3

Chris Müller

·

Published

2022-06-17

·

Updated

2022-07-19

·

CVE-2022-33154

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 schema extension versions prior to 1.13.1 TYPO3 schema extension versions 2.x prior to 2.5.1
Description The issue allows for XSS due to the failure to properly encode user input for output in HTML context. A TYPO3 backend user account is required to exploit this issue.
Recommendations For versions prior to 1.13.1, update to version 1.13.1 or later. For versions 2.x prior to 2.5.1, update to version 2.5.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-33154
GHSA-374W-GWQR-FMXG

Affected Products

Typo3