PT-2024-25812 · Typo3 · Typo3
Andreas Kienast
·
Published
2024-05-14
·
Updated
2025-01-21
·
CVE-2024-34355
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TYPO3 versions 13.0.0 through 13.1.0
Description
The history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript execution, adversaries can still inject malicious HTML markup. Exploiting this issue requires a valid backend user account.
Recommendations
Update to TYPO3 version 13.1.1 to fix the problem.
Exploit
Fix
XSS
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Typo3