CVE-2020-11064

MEDIUM

TYPO3 CMS >=9.0.0 <9.5.17, >=10.0.0 <10.4.2 - XSS

Title source: llm
STIX 2.1

Description

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, it has been discovered that HTML placeholder attributes containing data of other database records are vulnerable to cross-site scripting. A valid backend user account is needed to exploit this vulnerability. This has been fixed in 9.5.17 and 10.4.2.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0021
EPSS Percentile 42.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (3)
typo3/cms 10.0.0 - 10.4.2Packagist
typo3/cms-core 9.0.0 - 9.5.17Packagist
typo3/typo3 9.0.0 - 9.5.17
Published May 13, 2020
Tracked Since Feb 18, 2026