logo

Database

Server side cross-site scripting In typo3/cms

Description

Typo3 XSS Vulnerability The page module in TYPO3 before 8.7.11 has XSS via $GLOBALS['TYPO3_CONF_VARS']['SYS']['sitename'], as demonstrated by an admin entering a crafted site name during the installation process.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions