CVE-2020-15241
published 2020-10-08CVE-2020-15241: TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripting when…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.95%
56.9th percentile
TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripting when making use of the ternary conditional operator in templates like `{showFullName ? fullName : defaultValue}`. Updated versions of this package are bundled in following TYPO3 (`typo3/cms-core`) versions as well: TYPO3 v8.7.25 (using `typo3fluid/fluid` v2.5.4) and TYPO3 v9.5.6 (using `typo3fluid/fluid` v2.6.1).
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| typo3 | cms | >= 8.0.0 < 8.7.25 | 8.7.25 |
| typo3 | cms | >= 9.0.0 < 9.5.6 | 9.5.6 |
| typo3 | cms-core | >= 8.0.0 < 8.7.25 | 8.7.25 |
| typo3 | cms-core | >= 9.0.0 < 9.5.6 | 9.5.6 |
| typo3 | fluid | — | — |
| typo3 | fluid | — | — |
| typo3 | fluid | — | — |
| typo3 | fluid | — | — |
| typo3 | fluid | — | — |
| typo3 | fluid | — | — |
| typo3 | fluid | — | — |
| typo3 | fluid_engine | < 2.0.5 | 2.0.5 |
| typo3 | fluid_engine | >= 2.1.0 < 2.1.4 | 2.1.4 |
| typo3 | fluid_engine | >= 2.2.0 < 2.2.1 | 2.2.1 |
| typo3 | fluid_engine | >= 2.3.0 < 2.3.5 | 2.3.5 |
| typo3 | fluid_engine | >= 2.4.0 < 2.4.1 | 2.4.1 |
| typo3 | fluid_engine | >= 2.5.0 < 2.5.5 | 2.5.5 |
| typo3 | fluid_engine | >= 2.6.0 < 2.6.1 | 2.6.1 |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3fluid | fluid | >= 2.0.0 < 2.0.5 | 2.0.5 |
| typo3fluid | fluid | >= 2.1.0 < 2.1.4 | 2.1.4 |
| typo3fluid | fluid | >= 2.2.0 < 2.2.1 | 2.2.1 |
| typo3fluid | fluid | >= 2.3.0 < 2.3.5 | 2.3.5 |
| typo3fluid | fluid | >= 2.4.0 < 2.4.1 | 2.4.1 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Cross-Site Scripting in ternary conditional operator
osv·2020-10-08
CVE-2020-15241 [MEDIUM] Cross-Site Scripting in ternary conditional operator
Cross-Site Scripting in ternary conditional operator
> ### Meta
> * CVSS: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N/E:F/RL:O/RC:C`(5.0)
> * CWE-79
---
:information_source: This vulnerability has been fixed in May 2019 already, CVE and GHSA were assigned later in October 2020
---
### Problem
It has been discovered that the Fluid Engine (package `typo3fluid/fluid`) is vulnerable to cross-site scripting when making use of the ternary conditional operator in templates like the following.
```
{showFullName ? fullName : defaultValue}
```
### Solution
Update to versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 of this `typo3fluid/fluid` package that fix the problem described.
Updated versions of this package are bundled in following TYPO3 (`typo3/cms-core`) releases:
* TYPO3
GHSA
Cross-Site Scripting in ternary conditional operator
ghsa·2020-10-08
CVE-2020-15241 [MEDIUM] CWE-601 Cross-Site Scripting in ternary conditional operator
Cross-Site Scripting in ternary conditional operator
> ### Meta
> * CVSS: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N/E:F/RL:O/RC:C`(5.0)
> * CWE-79
---
:information_source: This vulnerability has been fixed in May 2019 already, CVE and GHSA were assigned later in October 2020
---
### Problem
It has been discovered that the Fluid Engine (package `typo3fluid/fluid`) is vulnerable to cross-site scripting when making use of the ternary conditional operator in templates like the following.
```
{showFullName ? fullName : defaultValue}
```
### Solution
Update to versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 of this `typo3fluid/fluid` package that fix the problem described.
Updated versions of this package are bundled in following TYPO3 (`typo3/cms-core`) releases:
* TYPO3
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/TYPO3/Fluid/commit/9ef6a8ffff2e812025fc0701b4ce72eea6911a3dhttps://github.com/TYPO3/Fluid/security/advisories/GHSA-7733-hjv6-4h47https://typo3.org/security/advisory/typo3-core-sa-2019-013https://github.com/TYPO3/Fluid/commit/9ef6a8ffff2e812025fc0701b4ce72eea6911a3dhttps://github.com/TYPO3/Fluid/security/advisories/GHSA-7733-hjv6-4h47https://typo3.org/security/advisory/typo3-core-sa-2019-013
2020-10-08
Published