PT-2025-11682 · Typo3 · Clickstorm Seo Extension

Published

2025-03-18

·

Updated

2025-03-19

·

CVE-2025-30081

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Clickstorm SEO extension for TYPO3 versions prior to 6.7.0 Clickstorm SEO extension for TYPO3 versions prior to 7.4.0 Clickstorm SEO extension for TYPO3 versions prior to 8.3.0 Clickstorm SEO extension for TYPO3 versions prior to 9.2.0
Description The issue exists due to inadequate protection of the webpage structure. It allows a remote attacker to conduct cross-site scripting attacks. A logged-in backend user can exploit improperly encoded user input to create output in the HTML context using the TYPO3 backend user interface.
Recommendations For versions prior to 6.7.0, update to version 6.7.0 or later. For versions prior to 7.4.0, update to version 7.4.0 or later. For versions prior to 8.3.0, update to version 8.3.0 or later. For versions prior to 9.2.0, update to version 9.2.0 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03800
CVE-2025-30081
GHSA-VMGW-24W6-9V82

Affected Products

Clickstorm Seo Extension