CVE-2015-5956: XSS
Backend: Non-Persistent Cross-Site Scripting
Other sources
The sanitizeLocalUrl function in TYPO3 6.x before 6.2.15, 7.x before 7.4.0, 4.5.40, and earlier allows remote authenticated users to bypass the XSS filter and conduct cross-site scripting (XSS) attacks via a base64 encoded data URI, as demonstrated by the (1) returnUrl parameter to showrechis.php and the (2) redirecturl parameter to index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5956?
CVE-2015-5956 has been classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-5956?
To resolve CVE-2015-5956, upgrade TYPO3 to versions 6.2.15, 7.4.0, or later.
Who is affected by CVE-2015-5956?
CVE-2015-5956 affects TYPO3 versions prior to 6.2.15 and 7.4.0, including 4.5.40 and earlier.
What types of attacks can CVE-2015-5956 enable?
CVE-2015-5956 can enable remote authenticated users to conduct cross-site scripting (XSS) attacks.
Is there a workaround for CVE-2015-5956?
There are no effective workarounds for CVE-2015-5956 other than upgrading to a patched version.