CVE-2021-21358
MEDIUMTYPO3 < 10.4.14 - Authenticated Stored Cross-Site Scripting in Form Designer Module
Title source: llmDescription
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that the Form Designer backend module of the Form Framework is vulnerable to cross-site scripting. A valid backend user account with access to the form module is needed to exploit this vulnerability. This is fixed in versions 10.4.14, 11.1.1.
References (3)
Core 3
Core References
Third Party Advisory x_refsource_confirm
https://github.com/TYPO3/TYPO3.CMS/security/advisories/GHSA-x79j-wgqv-g8h2
Release Notes, Third Party Advisory x_refsource_misc
https://packagist.org/packages/typo3/cms-form
Vendor Advisory x_refsource_misc
https://typo3.org/security/advisory/typo3-core-sa-2021-004
Scores
CVSS v3
5.4
EPSS
0.0038
EPSS Percentile
59.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (4)
typo3/cms
10.0.0 - 10.4.14Packagist
typo3/cms-core
10.0.0 - 10.4.14Packagist
typo3/cms-form
10.2.0 - 10.4.14Packagist
typo3/typo3
10.2.0 - 10.4.14
Published
Mar 23, 2021
Tracked Since
Feb 18, 2026