CVE-2015-5956Cross-site Scripting in CMS

Severity
3.5LOWNVD
EPSS
0.2%
top 61.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 16
Latest updateMay 14

Description

The sanitizeLocalUrl function in TYPO3 6.x before 6.2.15, 7.x before 7.4.0, 4.5.40, and earlier allows remote authenticated users to bypass the XSS filter and conduct cross-site scripting (XSS) attacks via a base64 encoded data URI, as demonstrated by the (1) returnUrl parameter to show_rechis.php and the (2) redirect_url parameter to index.php.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages2 packages

Packagisttypo3/cms6.06.2.15+2
NVDtypo3/typo34.5.40+45

🔴Vulnerability Details

3
OSV
TYPO3 cross-site scripting (XSS)2022-05-14
GHSA
TYPO3 cross-site scripting (XSS)2022-05-14
CVEList
CVE-2015-5956: The sanitizeLocalUrl function in TYPO3 62015-09-16
CVE-2015-5956 — Cross-site Scripting in Typo3 CMS | cvebase