Meta
- CVSS v3.1: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:F/RL:O/RC:C
- CWE-79
Problem
It has been discovered that HTML placeholder
attributes containing data of other database records are vulnerable to cross-site scripting. A valid backend user account is needed to exploit this vulnerability.
Solution
Update to TYPO3 versions 9.5.17 or 10.4.2 that fix the problem described.
Credits
Thanks to Florian Weiss who reported this issue and to TYPO3 active contributor Markus Klein who fixed the issue.
References
Problem
It has been discovered that HTML
placeholder
attributes containing data of other database records are vulnerable to cross-site scripting. A valid backend user account is needed to exploit this vulnerability.Solution
Update to TYPO3 versions 9.5.17 or 10.4.2 that fix the problem described.
Credits
Thanks to Florian Weiss who reported this issue and to TYPO3 active contributor Markus Klein who fixed the issue.
References