CVE-2019-12748: XSS
Published Jun 25, 2019
·Updated
Cross-Site Scripting in Link Handling
Other sources
TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS.
Affected Software
8 affected componentsFixes available
composer/typo3/cms>=8.0.0, <8.7.27, >=9.0.0, <9.5.8
composer/typo3/cms-core>=8.0.0, <8.7.27, >=9.0.0, <9.5.8
composer/typo3/cms>=9.0.0<9.5.8
9.5.8
composer/typo3/cms>=8.0.0<8.7.27
8.7.27
composer/typo3/cms-core>=9.0.0<9.5.8
9.5.8
composer/typo3/cms-core>=8.0.0<8.7.27
8.7.27
Typo3 TYPO3>=8.3.0<=8.7.26
Typo3 TYPO3>=9.0.0<=9.5.7
Event History
Jun 25, 2019
Advisory Published
06:39 AM
Jul 9, 2019
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-12748?
CVE-2019-12748 has been rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2019-12748?
To remediate CVE-2019-12748, upgrade TYPO3 to version 8.7.27 or 9.5.8.
3
Which versions of TYPO3 are affected by CVE-2019-12748?
CVE-2019-12748 affects TYPO3 versions from 8.3.0 to 8.7.26 and from 9.0.0 to 9.5.7.
4
What type of vulnerability is CVE-2019-12748?
CVE-2019-12748 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
5
Is CVE-2019-12748 present in TYPO3 9.5.8?
No, TYPO3 version 9.5.8 is not affected by CVE-2019-12748 as it contains the fix for this vulnerability.