CVE-2024-34355

LOW

TYPO3 <13.1.1 - XSS

Title source: llm
STIX 2.1

Description

TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript execution, adversaries can still inject malicious HTML markup. Exploiting this vulnerability requires a valid backend user account. TYPO3 version 13.1.1 fixes the problem described.

Scores

CVSS v3 3.5
EPSS 0.0062
EPSS Percentile 70.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-116
Status published
Products (2)
typo3/cms-core 13.0.0 - 13.1.1Packagist
typo3/typo3 13.0.0 - 13.1.1
Published May 14, 2024
Tracked Since Feb 18, 2026