CVE-2018-6905

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
08/04/2018
Last modified:
09/05/2018

Description

The page module in TYPO3 before 8.7.11, and 9.1.0, has XSS via $GLOBALS['TYPO3_CONF_VARS']['SYS']['sitename'], as demonstrated by an admin entering a crafted site name during the installation process.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* 8.7.11 (excluding)
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* 9.0.0 (including) 9.1.0 (excluding)