First published: Tue Jun 14 2022(Updated: )
TYPO3-CORE-SA-2022-004: Cross-Site Scripting in Frontend Login Mailer
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/typo3/cms-core | >=10.0.0<10.4.29>=11.0.0<11.5.11 | |
composer/typo3/cms | >=10.0.0<10.4.29>=11.0.0<11.5.11 | |
Typo3 Typo3 | >=9.0.0<9.5.35 | |
Typo3 Typo3 | >=10.0.0<10.4.29 | |
Typo3 Typo3 | >=11.0.0<11.5.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
TYPO3-CORE-SA-2022-004 is a vulnerability in TYPO3, an open source web content management system, that allows for cross-site scripting (XSS) attacks in the frontend login mailer.
The severity of TYPO3-CORE-SA-2022-004 is medium with a score of 5.4.
TYPO3 versions 9.5.34 ELTS, 10.4.29, and 11.5.11 are affected by TYPO3-CORE-SA-2022-004.
To fix TYPO3-CORE-SA-2022-004, upgrade to TYPO3 versions 9.5.35 ELTS, 10.4.30, or 11.5.12.
You can find more information about TYPO3-CORE-SA-2022-004 in the TYPO3 security advisory TYPO3-CORE-SA-2022-004.