Headline
GHSA-hww5-6x85-mc24: Typo3 Arbitrary Code Execution and Cross-Site Scripting in Backend API
Backend API configuration using Page TSconfig is vulnerable to arbitrary code execution and cross-site scripting. TSconfig fields of page properties in backend forms can be used to inject malicious sequences. Field tsconfig_includes is vulnerable to directory traversal leading to same scenarios as having direct access to TSconfig settings.
A valid backend user account having access to modify values for fields pages.TSconfig and pages.tsconfig_includes is needed in order to exploit this vulnerability.
- GitHub Advisory Database
- GitHub Reviewed
- GHSA-hww5-6x85-mc24
Typo3 Arbitrary Code Execution and Cross-Site Scripting in Backend API
Moderate severity GitHub Reviewed Published Jun 5, 2024 to the GitHub Advisory Database • Updated Jun 5, 2024
Package
Affected versions
>= 8.0.0, < 8.7.27
>= 9.0.0, < 9.5.8
Patched versions
8.7.27
9.5.8
Published to the GitHub Advisory Database
Jun 5, 2024