Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-qffc-gwpp-m2xr: XML External Entity (XXE) Processing in TYPO3 Core

All XML processing within the TYPO3 CMS are vulnerable to XEE processing. This can lead to load internal and/or external (file) content within an XML structure. Furthermore it is possible to inject arbitrary files for an XML Denial of Service attack. For more information on that topic see https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing.

ghsa
#dos#git#php

XML External Entity (XXE) Processing in TYPO3 Core

High severity GitHub Reviewed Published Jun 4, 2024 to the GitHub Advisory Database • Updated Jun 4, 2024

ghsa: Latest News

GHSA-6jrf-rcjf-245r: changedetection.io path traversal using file URI scheme without supplying hostname