Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-qmwf-j7g7-f5jw: Cross-Site Scripting in third party library mso/idna-convert

Make sure to not expose the vendor directory to the publicly accessible document root. In composer managed installation, make sure to configure a dedicated web folder. In general it is recommended to not expose the complete typo3_src sources folder in the document root.

ghsa
#xss#web#git

Cross-Site Scripting in third party library mso/idna-convert

Moderate severity GitHub Reviewed Published Jun 5, 2024 to the GitHub Advisory Database

ghsa: Latest News

GHSA-pxg6-pf52-xh8x: cookie accepts cookie name, path, and domain with out of bounds characters