Attackers can exploit a cross-site scripting vulnerability in the TYPO3 content management system to inject malicious HTML code.
The security advisory, which is primarily aimed at developers, reads as follows: "The TYPO3 core component GeneralUtility::getIndpEnv() uses the unfiltered server environment variable PATH_INFO, allowing attackers to inject malicious content. In combination with the TypoScript setting config.absRefPrefix=auto, an attacker can inject malicious HTML code into pages that have not yet been rendered and cached. The injected values are then cached and served to other visitors to the website."
The Common Vulnerability Scoring System rates the vulnerability as “high” (CVE-2023-24814, CVSS 8.8).
The vulnerability affects Typo3 versions 8.7.0–8.7.50, 9.0.0–9.5.39, 10.0.0–10.4.34, 11.0.0–11.5.22, and 12.0.0–12.1.3. The project has recently made updated versions 12.2.0, 11.5.23, and 10.4.36 available for download on the TYPO3 website. Due to the severity of the vulnerability, administrators are advised to download and install these updates as soon as possible.
If you host your TYPO3 website project with us, you benefit from our automatic update service. As soon as a new version is released, the update is applied immediately.
Automatisch übersetzt. Ohne Gewähr für Vollständigkeit und Richtigkeit.