
We found results for “”
CVE-2020-26227
Good to know:

Date: November 23, 2020
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fluid) of the TYPO3 core is vulnerable to cross-site scripting passing user-controlled data as argument to Fluid view helpers. Update to TYPO3 versions 9.5.23 or 10.4.10 that fix the problem described.
Language: PHP
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix

Upgrade Version
Upgrade to version typo3/cms-form - v8.7.19;typo3/cms-form - 10.4.x-dev;typo3/cms-form - v9.5.10;typo3/cms-form - v10.4.10;typo3/cms-form - v8.7.28;typo3/cms-form - v9.5.23;typo3/cms-form - v9.4.0;typo3/cms-form - v10.1.0;typo3/cms-form - v8.7.7;typo3/cms-fluid - v8.7.28;typo3/cms-fluid - v10.1.0;typo3/cms-fluid - v8.7.32;typo3/cms-fluid - v9.5.23;typo3/cms-fluid - v8.7.21;typo3/cms-fluid - v10.4.10;typo3/cms-fluid - v9.5.10;typo3/cms-fluid - v9.2.0;typo3/cms-fluid - 10.4.x-dev;typo3/cms-fluid - v9.3.0;typo3/cms - v9.5.13;typo3/cms - 8.7.16;typo3/cms - v9.5.5;typo3/cms - 8.7.18;typo3/cms - 8.7.7;typo3/cms - TYPO3_8-7-1;typo3/cms - 8.7.19;typo3/cms - v9.5.23;typo3/cms - 8.7.6;typo3/cms - 8.7.11;typo3/cms - 8.7.10;typo3/cms - 8.7.13;typo3/cms - 8.7.15;typo3/cms - 8.7.17;typo3/cms - v10.4.10;typo3/cms - v9.5.7;typo3/cms - 10.4.x-dev;typo3/cms - 8.7.26;typo3/cms - 8.7.12;typo3/cms - 8.7.8;typo3/cms - 8.7.14;typo3/cms - v9.4.0;typo3/cms - 8.7.9;typo3/cms - v9.5.2;typo3/cms-core - 10.4.x-dev;typo3/cms-core - v10.4.10;typo3/cms-core - v9.5.10;typo3/cms-core - v10.1.0;typo3/cms-core - v9.5.23;typo3/cms-core - v9.4.0;instituteweb/typo3-cms - no_fix;instituteweb/typo3-cms - 6.2.19;namelesscoder/cms-fluid - no_fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | CHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | NONE |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | MEDIUM |
Authentication (AU): | NONE |
Confidentiality (C): | NONE |
Integrity (I): | PARTIAL |
Availability (A): | NONE |
Additional information: |