CVE-2024-34356
MEDIUMTYPO3 <9.0.0-9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 1...
Title source: llmDescription
TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the form manager backend module is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to the form module. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1 fix the problem described.
References (5)
Core 5
Core References
Vendor Advisory x_refsource_confirm
https://github.com/TYPO3/typo3/security/advisories/GHSA-v6mw-h7w6-59w3
Patch x_refsource_misc
https://github.com/TYPO3/typo3/commit/2832e2f51f929aeddb5de7d667538a33ceda8156
Patch x_refsource_misc
https://github.com/TYPO3/typo3/commit/d0393a879a32fb4e3569acad6bdb5cda776be1e5
Patch x_refsource_misc
https://github.com/TYPO3/typo3/commit/e95a1224719efafb9cab2d85964f240fd0356e64
Vendor Advisory x_refsource_misc
https://typo3.org/security/advisory/typo3-core-sa-2024-008
Scores
CVSS v3
5.4
EPSS
0.0063
EPSS Percentile
70.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
typo3/cms-core
9.0.0 - 9.5.48Packagist
typo3/typo3
9.0.0 - 9.5.48
Published
May 14, 2024
Tracked Since
Feb 18, 2026