Headline
GHSA-qmwf-j7g7-f5jw: Cross-Site Scripting in third party library mso/idna-convert
Make sure to not expose the vendor directory to the publicly accessible document root. In composer managed installation, make sure to configure a dedicated web folder. In general it is recommended to not expose the complete typo3_src sources folder in the document root.
Cross-Site Scripting in third party library mso/idna-convert
Moderate severity GitHub Reviewed Published Jun 5, 2024 to the GitHub Advisory Database