Reflected cross-site scripting (XSS) In typo3/cms

Description

Duplicate Advisory: TYPO3 Cross-Site Scripting vulnerability in typolinks

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-j5v7-9xr5-m7gx. This link is maintained to preserve external references.

Original Description

All link fields within the TYPO3 installation are vulnerable to Cross-Site Scripting as authorized editors can insert javascript commands by using the url scheme javascript:.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions