TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that content elements of type _menu_ are vulnerable to cross-site scripting when their referenced items get previewed in the page module. A valid backend user account is needed to exploit this vulnerability. This is fixed in versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-0723 TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that content elements of type _menu_ are vulnerable to cross-site scripting when their referenced items get previewed in the page module. A valid backend user account is needed to exploit this vulnerability. This is fixed in versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1.
Github GHSA Github GHSA GHSA-x7hc-x7fm-f7qh Cross-Site Scripting in Content Preview (CType menu)
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-03T18:09:15.935Z

Reserved: 2020-12-22T00:00:00

Link: CVE-2021-21370

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-03-23T02:15:12.987

Modified: 2024-11-21T05:48:13.000

Link: CVE-2021-21370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses