PT-2024-25812 · Typo3 · Typo3

·

CVE-2024-34355

·

Published

2024-05-14

·

Updated

2025-01-21

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 versions 13.0.0 through 13.1.0
Description The history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript execution, adversaries can still inject malicious HTML markup. Exploiting this issue requires a valid backend user account.
Recommendations Update to TYPO3 version 13.1.1 to fix the problem.

Exploit

Fix

DoS

Improper Encoding or Escaping of Output

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-34355
GHSA-XJWX-78X7-Q6JC

Affected Products

Typo3