PT-2024-40190 · Packagist · Typo3/Cms-Core

Published

2024-05-30

·

Updated

2024-05-30

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: No specific software or version information is provided.
Description: The issue arises from improper encoding of user input, making the login status display susceptible to cross-site scripting in the website frontend. To exploit this, a valid user account is required, which could be either a backend user or a frontend user with the ability to modify their user profile. Specifically, template patterns are affected, including FEUSER [fieldName] using the system extension felogin and <!--USERNAME--> for regular frontend rendering, where the pattern can be individually defined using the TypoScript setting config.USERNAME substToken.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

GHSA-8C25-VJ2W-P72J

Affected Products

Typo3/Cms-Core