Description
The ke_search (aka Faceted Search) extension before 4.0.3, 4.1.x through 4.6.x before 4.6.6, and 5.x before 5.0.2 for TYPO3 allows XSS via indexed data.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1779 | The ke_search (aka Faceted Search) extension before 4.0.3, 4.1.x through 4.6.x before 4.6.6, and 5.x before 5.0.2 for TYPO3 allows XSS via indexed data. |
Github GHSA |
GHSA-f4m6-x2xj-jc7w | ke_search (aka Faceted Search) vulnerable to Cross-Site Scripting |
References
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2023-004 |
|
History
Wed, 11 Dec 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-11T20:19:31.739Z
Reserved: 2023-06-16T00:00:00.000Z
Link: CVE-2023-35783
Updated: 2024-08-02T16:30:45.354Z
Status : Modified
Published: 2023-06-16T15:15:10.037
Modified: 2024-11-21T08:08:41.673
Link: CVE-2023-35783
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD
Github GHSA