CVE-2021-21370Cross-site Scripting in Typo3

Severity
5.4MEDIUMNVD
EPSS
0.3%
top 43.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 23

Description

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that content elements of type _menu_ are vulnerable to cross-site scripting when their referenced items get previewed in the page module. A valid backend user account is needed to exploit this vulnerability. This is fixed in versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages5 packages

Packagisttypo3/cms-backend7.0.07.6.51+4
Packagisttypo3/cms10.0.010.4.14+2
NVDtypo3/typo37.0.07.6.51+4
Packagisttypo3/cms-core10.0.010.4.14+2
CVEListV5typo3/typo3.cms5 versions+4

🔴Vulnerability Details

3
OSV
Cross-Site Scripting in Content Preview (CType menu)2021-03-23
GHSA
Cross-Site Scripting in Content Preview (CType menu)2021-03-23
CVEList
Cross-Site Scripting in Content Preview (CType menu)2021-03-23
CVE-2021-21370 — Cross-site Scripting in Typo3 | cvebase