PT-2022-23198 · Typo3 · Typo3

Frank Nägler

·

Published

2022-09-13

·

Updated

2024-03-06

·

CVE-2022-36108

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions TYPO3 versions prior to 10.4.32 TYPO3 versions prior to 11.5.16
Description The f:asset.css view helper in TYPO3 is vulnerable to cross-site scripting when user input is passed as variables to the CSS.
Recommendations Update to TYPO3 version 10.4.32 or 11.5.16 to fix the issue. As a temporary workaround, consider disabling the f:asset.css view helper until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-TYPO3-2022-36108
CVE-2022-36108
GHSA-FV2M-9249-QX85

Affected Products

Typo3