CVE-2024-34357
MEDIUMTYPO3 <9.0.0-<9.5.48 ELTS,<10.4.45 ELTS,<11.5.37 LTS,<12.4.15 LTS,<...
Title source: llmDescription
TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, failing to properly encode user-controlled values in file entities, the `ShowImageController` (`_eID tx_cms_showpic_`) is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to file entities. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.
References (5)
Core 5
Core References
Vendor Advisory x_refsource_confirm
https://github.com/TYPO3/typo3/security/advisories/GHSA-hw6c-6gwq-3m3m
Patch x_refsource_misc
https://github.com/TYPO3/typo3/commit/376474904f6b9a54dc1b785a2e45277cbd13b0d7
Patch x_refsource_misc
https://github.com/TYPO3/typo3/commit/b31d05d1da3eeaeead2d19eb43b1c3f9c88e15ee
Patch x_refsource_misc
https://github.com/TYPO3/typo3/commit/d774642381354d3bf5095a5a26e18acd2767f0b1
Vendor Advisory x_refsource_misc
https://typo3.org/security/advisory/typo3-core-sa-2024-009
Scores
CVSS v3
5.4
EPSS
0.0063
EPSS Percentile
70.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
typo3/cms-core
9.0.0 - 9.5.48Packagist
typo3/typo3
9.0.0 - 9.5.48
Published
May 14, 2024
Tracked Since
Feb 18, 2026