TYPO3 Cross-Site Scripting in Fluid ViewHelpers
Moderate severity
GitHub Reviewed
Published
May 30, 2024
to the GitHub Advisory Database
Package
Affected versions
>= 8.0.0, < 8.7.23
>= 9.0.0, < 9.5.4
Patched versions
8.7.23
9.5.4
Description
Published to the GitHub Advisory Database
May 30, 2024
Reviewed
May 30, 2024
Failing to properly encode user input, templates using built-in Fluid ViewHelpers are vulnerable to cross-site scripting.
References