CVE-2020-26227
published 2020-11-23CVE-2020-26227: TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fluid) of…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.71%
49.1th percentile
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system extension Fluid (typo3/cms-fluid) of the TYPO3 core is vulnerable to cross-site scripting passing user-controlled data as argument to Fluid view helpers. Update to TYPO3 versions 9.5.23 or 10.4.10 that fix the problem described.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| typo3 | cms | >= 10.0.0 < 10.4.10 | 10.4.10 |
| typo3 | cms | >= 8.7.0 < 8.7.38 | 8.7.38 |
| typo3 | cms | >= 9.0.0 < 9.5.23 | 9.5.23 |
| typo3 | cms-core | >= 10.0.0 < 10.4.10 | 10.4.10 |
| typo3 | cms-core | >= 8.7.0 < 8.7.38 | 8.7.38 |
| typo3 | cms-core | >= 9.0.0 < 9.5.23 | 9.5.23 |
| typo3 | typo3 | >= 10.0.0 < 10.4.10 | 10.4.10 |
| typo3 | typo3 | >= 6.2.0 < 6.2.54 | 6.2.54 |
| typo3 | typo3 | >= 7.6.0 < 7.6.48 | 7.6.48 |
| typo3 | typo3 | >= 8.7.0 < 8.7.38 | 8.7.38 |
| typo3 | typo3 | >= 9.0.0 < 9.5.23 | 9.5.23 |
| typo3 | typo3.cms | — | — |
| typo3 | typo3.cms | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Cross-Site Scripting in Fluid view helpers
osv·2020-12-21
CVE-2020-26227 [MEDIUM] Cross-Site Scripting in Fluid view helpers
Cross-Site Scripting in Fluid view helpers
> ### Meta
> * CVSS: `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:F/RL:O/RC:C` (5.7)
> * CWE-79
### Problem
It has been discovered that system extension Fluid (`typo3/cms-fluid`) of the TYPO3 core is vulnerable to cross-site scripting passing user-controlled data as argument to Fluid view helpers.
```
```
### Solution
Update to TYPO3 versions 9.5.23 or 10.4.10 that fix the problem described.
### Credits
Thanks to TYPO3 security team member Oliver Hader who reported this issue and to TYPO3 security team members Helmut Hummel & Oliver Hader who fixed the issue.
### References
* [TYPO3-CORE-SA-2020-010](https://typo3.org/security/advisory/typo3-core-sa-2020-010)
GHSA
Cross-Site Scripting in Fluid view helpers
ghsa·2020-12-21
CVE-2020-26227 [MEDIUM] CWE-79 Cross-Site Scripting in Fluid view helpers
Cross-Site Scripting in Fluid view helpers
> ### Meta
> * CVSS: `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:F/RL:O/RC:C` (5.7)
> * CWE-79
### Problem
It has been discovered that system extension Fluid (`typo3/cms-fluid`) of the TYPO3 core is vulnerable to cross-site scripting passing user-controlled data as argument to Fluid view helpers.
```
```
### Solution
Update to TYPO3 versions 9.5.23 or 10.4.10 that fix the problem described.
### Credits
Thanks to TYPO3 security team member Oliver Hader who reported this issue and to TYPO3 security team members Helmut Hummel & Oliver Hader who fixed the issue.
### References
* [TYPO3-CORE-SA-2020-010](https://typo3.org/security/advisory/typo3-core-sa-2020-010)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-11-23
Published