TYPO3
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*
- >= 13.0.0, <= 13.4.30
- >= 14.0.0, <= 14.3.2
A cross-site scripting vulnerability has been identified in TYPO3 CMS versions 13.0.0 prior to 13.4.31 and 14.0.0 prior to 14.3.2. Editors with the ability to create or modify page content could include unfiltered HTML in page titles. These titles were then stored in the search index and, when displayed in the frontend search results through the Indexed Search plugin, were rendered without proper output encoding. This lack of sanitization allowed for the injection of malicious scripts.
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Users are advised to update TYPO3 to versions 13.4.31 LTS or 14.3.3 LTS, which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.