TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripting when making use of the ternary conditional operator in templates like `{showFullName ? fullName : defaultValue}`. Updated versions of this package are bundled in following TYPO3 (`typo3/cms-core`) versions as well: TYPO3 v8.7.25 (using `typo3fluid/fluid` v2.5.4) and TYPO3 v9.5.6 (using `typo3fluid/fluid` v2.6.1).
2020-10-08T21:15:10.167
2024-11-21T05:05:10.170
Modified
CVSSv3.1: 4.7 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | typo3 | fluid_engine | < 2.0.5 | Yes |
Application | typo3 | fluid_engine | < 2.1.4 | Yes |
Application | typo3 | fluid_engine | < 2.2.1 | Yes |
Application | typo3 | fluid_engine | < 2.3.5 | Yes |
Application | typo3 | fluid_engine | < 2.4.1 | Yes |
Application | typo3 | fluid_engine | < 2.5.5 | Yes |
Application | typo3 | fluid_engine | < 2.6.1 | Yes |
Application | typo3 | typo3 | 8.7.25 | Yes |
Application | typo3 | typo3 | 9.5.6 | Yes |