Description
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fluid) of the TYPO3 core is vulnerable to cross-site scripting passing user-controlled data as argument to Fluid view helpers. Update to TYPO3 versions 9.5.23 or 10.4.10 that fix the problem described.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-1506 | TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fluid) of the TYPO3 core is vulnerable to cross-site scripting passing user-controlled data as argument to Fluid view helpers. Update to TYPO3 versions 9.5.23 or 10.4.10 that fix the problem described. |
Github GHSA |
GHSA-vqqx-jw6p-q3rf | Cross-Site Scripting in Fluid view helpers |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T15:56:03.033Z
Reserved: 2020-10-01T00:00:00.000Z
Link: CVE-2020-26227
No data.
Status : Modified
Published: 2020-11-23T21:15:12.047
Modified: 2024-11-21T05:19:35.430
Link: CVE-2020-26227
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA