TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript execution, adversaries can still inject malicious HTML markup. Exploiting this vulnerability requires a valid backend user account. TYPO3 version 13.1.1 fixes the problem described.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-1865 TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript execution, adversaries can still inject malicious HTML markup. Exploiting this vulnerability requires a valid backend user account. TYPO3 version 13.1.1 fixes the problem described.
Github GHSA Github GHSA GHSA-xjwx-78x7-q6jc TYPO3 vulnerable to an HTML Injection in the History Module
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 21 Jan 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Typo3
Typo3 typo3
CPEs cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
Vendors & Products Typo3
Typo3 typo3

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T02:51:11.144Z

Reserved: 2024-05-02T06:36:32.438Z

Link: CVE-2024-34355

cve-icon Vulnrichment

Updated: 2024-08-02T02:51:11.144Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-14T16:17:24.230

Modified: 2025-01-21T16:08:57.453

Link: CVE-2024-34355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.