CVE-2021-36785: XSS
Published Aug 13, 2021
·Updated
The miniorangesaml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.
Affected Software
1 affected component
miniOrange Saml Typo3<1.4.3
Event History
Aug 13, 2021
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-36785.
2
What is the severity of CVE-2021-36785?
The severity of CVE-2021-36785 is medium with a severity value of 5.4.
3
What is affected by this vulnerability?
The Miniorange Saml extension before 1.4.3 for TYPO3 is affected by this vulnerability.
4
What is the Common Vulnerability Enumeration (CWE) ID for this vulnerability?
The Common Vulnerability Enumeration (CWE) ID for this vulnerability is CWE-79.
5
How can I fix this vulnerability?
Update the Miniorange Saml extension to version 1.4.3 or later to fix this vulnerability.