CVE-2015-5956

TYPO3 < 4.5.40, 6.x < 6.2.15, 7.x < 7.4.0 - Authenticated Cross-Site Scripting via Base64 Data URI

Title source: llm
STIX 2.1

Description

The sanitizeLocalUrl function in TYPO3 6.x before 6.2.15, 7.x before 7.4.0, 4.5.40, and earlier allows remote authenticated users to bypass the XSS filter and conduct cross-site scripting (XSS) attacks via a base64 encoded data URI, as demonstrated by the (1) returnUrl parameter to show_rechis.php and the (2) redirect_url parameter to index.php.

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Sep/57
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033551
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/536464/100/0/threaded

Scores

EPSS 0.0017
EPSS Percentile 37.7%

Details

CWE
CWE-79
Status published
Products (47)
typo3/cms 6.0 - 6.2.15Packagist
typo3/typo3 6.0
typo3/typo3 6.0.1
typo3/typo3 6.0.2
typo3/typo3 6.0.3
typo3/typo3 6.0.4
typo3/typo3 6.0.5
typo3/typo3 6.0.6
typo3/typo3 6.0.7
typo3/typo3 6.0.8
... and 37 more
Published Sep 16, 2015
Tracked Since Feb 18, 2026