The open-source CMS TYPO3 tackles XSS vulnerabilities

In a recent software update, the maintainers of the open-source content management system TYPO3 fixed an XSS flaw.

Due to a parsing issue in the upstream package masterminds/html5, the XSS protection mechanism of PHP package typo3/Html-sanitizer was bypassed, resulting in a “malicious markup sequence with special HTML comments” not being filtered and sanitized, according to a GitHub advisory published on Tuesday.).

This issue has been fixed in typo3/cms-core versions 7.6.58, 8.7.48, 9.5.37, 10.4.32, and 11.5.16. This issue affects all previous versions of these release lines.

As the bug requires user interaction, it is classified as moderate severity, notching a CVSS score of 6.1. However, the number of active installations of TYPO3 is vast, despite its modest market share.

This free-to-use content management system has 2.43% of the CMS market, which translates to over 230,000 customers, 46% of whom are based in Germany.

Donations and membership subscriptions are the primary funding sources for the TYPO3 Association, which has around 900 members.

The bug was discovered by security researcher David Klein, while the patch was developed by Oliver Hader, the security team lead and core developer for TYPO3.

Share This Post

Facebook
Twitter
LinkedIn
Pinterest
Reddit

You May Also Like

Picture of Christopher Redus
Christopher Redus
Chris is an information security professional with over 10 years’ experience in building and managing complex security infrastructures. He has contributed to various published papers, spoken at numerous security conferences, and provides security consulting.

Hire a Professional Hacker Today!

Advertisement Form

About Us

About Us

Do you want to hire a hacker? Hireahackeronline.co is the internet's number 1 Hacker for Hire information center. You will get all the right information you need to guide you in making the right decision on how to hire a hacker. Get answers to questions like, how can I hire hacker? How can I find a hacker? And all you need to know about hiring a hacking service.

Get in Touch with Us

Don’t Miss Our News!

Subscribe to Hireahackeronline Newsletter and Get All Topical Information