PT-2022-21716 · Typo3 · Wp-Matomo Integration

Chris Müller

·

Published

2022-06-17

·

Updated

2024-03-06

·

CVE-2022-33156

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions matomo integration extension versions prior to 1.3.2
Description The issue allows for XSS due to the extension's failure to properly encode user input for output in HTML context. A TYPO3 backend user account is required to exploit this issue.
Recommendations For matomo integration extension versions prior to 1.3.2, update to version 1.3.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the extension to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-MATOMO-2022-33156
CVE-2022-33156
GHSA-GVXV-P9RV-GMCG

Affected Products

Wp-Matomo Integration