CVE-2023-24814Cross-site Scripting in Typo3

Severity
6.1MEDIUMNVD
CNA8.8
EPSS
0.9%
top 24.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 7
Latest updateFeb 8

Description

TYPO3 is a free and open source Content Management Framework released under the GNU General Public License. In affected versions the TYPO3 core component `GeneralUtility::getIndpEnv()` uses the unfiltered server environment variable `PATH_INFO`, which allows attackers to inject malicious content. In combination with the TypoScript setting `config.absRefPrefix=auto`, attackers can inject malicious HTML code to pages that have not been rendered and cached, yet. As a result, injected values would b

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

Packagisttypo3/cms-core12.0.012.2.0+4
Packagisttypo3/cms10.0.010.4.35+2
NVDtypo3/typo38.7.09.7.51+4
CVEListV5typo3/typo35 versions+4

Patches

🔴Vulnerability Details

3
GHSA
TYPO3 is vulnerable to Cross-Site Scripting via frontend rendering2023-02-08
OSV
TYPO3 is vulnerable to Cross-Site Scripting via frontend rendering2023-02-08
CVEList
Persisted Cross-Site Scripting in Frontend Rendering in typo32023-02-07
CVE-2023-24814 — Cross-site Scripting in Typo3 | cvebase