Allele Security Alert
ASA-2018-00080
Identifier(s)
ASA-2018-00080, TYPO3-CORE-SA-2018-007
Title
Cross-Site Scripting in Backend Modal Component
Vendor(s)
TYPO3 Association
Product(s)
TYPO3
Affected version(s)
TYPO3 7.1.0-7.6.31, 8.5.0-8.7.20 and 9.0.0-9.5.1
Fixed version(s)
TYPO3 versions 7.6.32, 8.7.21 or 9.5.2
Proof of concept
Unknown
Description
Failing to properly encode user input, notifications shown in modal windows in the TYPO3 backend are vulnerable to cross-site scripting. A valid backend user account is needed in order to exploit this vulnerability.
Technical details
Unknown
Credits
Joshua Westerheide and Frank Nägler (TYPO3 core team)
Reference(s)
TYPO3 9.5.2, 8.7.21 and 7.6.32 security releases published
https://typo3.org/article/typo3-952-8721-and-7632-security-releases-published/
TYPO3-CORE-SA-2018-007: Cross-Site Scripting in Backend Modal Component
https://typo3.org/security/advisory/typo3-core-sa-2018-007/
[SECURITY] Prevent XSS in modal component and PageTree
https://github.com/TYPO3/TYPO3.CMS/commit/02cd5c97228cba477d16c68e28309ce25c433ce9
[TYPO3-announce] Announcing TYPO3 v9.5.2, v8.7.21 and v7.6.32 security releases
http://lists.typo3.org/pipermail/typo3-announce/2018/000435.html
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: February 1, 2019