CVE-2024-34356
Description
TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the form manager backend module is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to the form module. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1 fix the problem described.
CWE
- CWE-79 — CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected
- TYPO3 / typo3 — v=>= 9.0.0, < 9.5.48 [affected]; v=>= 10.0.0, < 10.4.45 [affected]; v=>= 11.0.0, < 11.5.37 [affected]; v=>= 12.0.0, < 12.4.15 [affected]; v=>= 13.0.0, < 13.1.1 [affected]
CVSS
- 3.1 score=5.4 severity=MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References
- https://github.com/TYPO3/typo3/security/advisories/GHSA-v6mw-h7w6-59w3 x_refsource_CONFIRM
- https://github.com/TYPO3/typo3/commit/2832e2f51f929aeddb5de7d667538a33ceda8156 x_refsource_MISC
- https://github.com/TYPO3/typo3/commit/d0393a879a32fb4e3569acad6bdb5cda776be1e5 x_refsource_MISC
- https://github.com/TYPO3/typo3/commit/e95a1224719efafb9cab2d85964f240fd0356e64 x_refsource_MISC
- https://typo3.org/security/advisory/typo3-core-sa-2024-008 x_refsource_MISC
Source
cvelistV5-main/cves/2024/34xxx/CVE-2024-34356.json