Description
TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript execution, adversaries can still inject malicious HTML markup. Exploiting this vulnerability requires a valid backend user account. TYPO3 version 13.1.1 fixes the problem described.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1865 | TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript execution, adversaries can still inject malicious HTML markup. Exploiting this vulnerability requires a valid backend user account. TYPO3 version 13.1.1 fixes the problem described. |
Github GHSA |
GHSA-xjwx-78x7-q6jc | TYPO3 vulnerable to an HTML Injection in the History Module |
References
History
Tue, 21 Jan 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Typo3
Typo3 typo3 |
|
| CPEs | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Typo3
Typo3 typo3 |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T02:51:11.144Z
Reserved: 2024-05-02T06:36:32.438Z
Link: CVE-2024-34355
Updated: 2024-08-02T02:51:11.144Z
Status : Analyzed
Published: 2024-05-14T16:17:24.230
Modified: 2025-01-21T16:08:57.453
Link: CVE-2024-34355
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA