You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Cross-Site Scripting in TYPO3 CMS Link Handling
Moderate severity
GitHub Reviewed
Published
May 12, 2020
in
TYPO3/typo3
•
Updated Feb 5, 2024
It has been discovered that link tags generated by typolink functionality are vulnerable to cross-site scripting - properties being assigned as HTML attributes have not been parsed correctly.
Update to TYPO3 versions 9.5.17 or 10.4.2 that fix the problem described.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Learn more on MITRE.
It has been discovered that link tags generated by
typolink
functionality are vulnerable to cross-site scripting - properties being assigned as HTML attributes have not been parsed correctly.Update to TYPO3 versions 9.5.17 or 10.4.2 that fix the problem described.
References
References