TYPO3 vulnerable to Cross-Site Scripting in the ShowImageController
Package
Affected versions
>= 9.0.0, <= 9.5.47
>= 10.0.0, <= 10.4.44
>= 11.0.0, <= 11.5.36
>= 12.0.0, <= 12.4.14
>= 13.0.0, <= 13.1.0
Patched versions
9.5.48
10.4.45
11.5.37
12.4.15
13.1.1
Description
Published by the National Vulnerability Database
May 14, 2024
Published to the GitHub Advisory Database
May 14, 2024
Reviewed
May 14, 2024
Last updated
May 14, 2024
Problem
Failing to properly encode user-controlled values in file entities, the
ShowImageController
(eID tx_cms_showpic) is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to file entities.Solution
Update to TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 that fix the problem described.
Credits
Thanks to TYPO3 security team member Torben Hansen who reported this issue and to TYPO3 core & security team member Oliver Hader who fixed the issue.
References
References