icon

We found results for “

CVE-2020-26227

Good to know:

icon

Date: November 23, 2020

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fluid) of the TYPO3 core is vulnerable to cross-site scripting passing user-controlled data as argument to Fluid view helpers. Update to TYPO3 versions 9.5.23 or 10.4.10 that fix the problem described.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version typo3/cms-form - v8.7.19;typo3/cms-form - 10.4.x-dev;typo3/cms-form - v9.5.10;typo3/cms-form - v10.4.10;typo3/cms-form - v8.7.28;typo3/cms-form - v9.5.23;typo3/cms-form - v9.4.0;typo3/cms-form - v10.1.0;typo3/cms-form - v8.7.7;typo3/cms-fluid - v8.7.28;typo3/cms-fluid - v10.1.0;typo3/cms-fluid - v8.7.32;typo3/cms-fluid - v9.5.23;typo3/cms-fluid - v8.7.21;typo3/cms-fluid - v10.4.10;typo3/cms-fluid - v9.5.10;typo3/cms-fluid - v9.2.0;typo3/cms-fluid - 10.4.x-dev;typo3/cms-fluid - v9.3.0;typo3/cms - v9.5.13;typo3/cms - 8.7.16;typo3/cms - v9.5.5;typo3/cms - 8.7.18;typo3/cms - 8.7.7;typo3/cms - TYPO3_8-7-1;typo3/cms - 8.7.19;typo3/cms - v9.5.23;typo3/cms - 8.7.6;typo3/cms - 8.7.11;typo3/cms - 8.7.10;typo3/cms - 8.7.13;typo3/cms - 8.7.15;typo3/cms - 8.7.17;typo3/cms - v10.4.10;typo3/cms - v9.5.7;typo3/cms - 10.4.x-dev;typo3/cms - 8.7.26;typo3/cms - 8.7.12;typo3/cms - 8.7.8;typo3/cms - 8.7.14;typo3/cms - v9.4.0;typo3/cms - 8.7.9;typo3/cms - v9.5.2;typo3/cms-core - 10.4.x-dev;typo3/cms-core - v10.4.10;typo3/cms-core - v9.5.10;typo3/cms-core - v10.1.0;typo3/cms-core - v9.5.23;typo3/cms-core - v9.4.0;instituteweb/typo3-cms - no_fix;instituteweb/typo3-cms - 6.2.19;namelesscoder/cms-fluid - no_fix

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): MEDIUM
Authentication (AU): NONE
Confidentiality (C): NONE
Integrity (I): PARTIAL
Availability (A): NONE
Additional information:

Do you need more information?

Contact Us