typo3/cms Security Advisories for v11.5.13 (13)
-
[HIGH] TYPO3-CORE-SA-2023-001: Persisted Cross-Site Scripting in Frontend Rendering
PKSA-2dds-jbmg-2pyg CVE-2023-24814 GHSA-r4f8-f93x-5qh3
Affected version: >=10.0.0,<10.4.35|>=11.0.0,<11.5.23|>=12.0.0,<12.2.0
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] TYPO3-CORE-SA-2022-017: By-passing Cross-Site Scripting Protection in HTML Sanitizer
PKSA-836z-82j1-zt6j CVE-2022-23499 GHSA-hvwx-qh2h-xcfj
Affected version: >=10.0.0,<10.4.33|>=11.0.0,<11.5.20|>=12.0.0,<12.1.1
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] TYPO3-CORE-SA-2022-016: Sensitive Information Disclosure via YAML Placeholder Expressions in Site Configuration
PKSA-72zd-w89p-dd55 CVE-2022-23504 GHSA-8w3p-qh3x-6gjr
Affected version: >=10.0.0,<10.4.33|>=11.0.0,<11.5.20|>=12.0.0,<12.1.1
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] TYPO3-CORE-SA-2022-015: Arbitrary Code Execution via Form Framework
PKSA-hnp1-st4h-rkt2 CVE-2022-23503 GHSA-c5wx-6c2c-f7rm
Affected version: >=10.0.0,<10.4.33|>=11.0.0,<11.5.20|>=12.0.0,<12.1.1
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] TYPO3-CORE-SA-2022-014: Insufficient Session Expiration after Password Reset
PKSA-cm5x-bvw7-z1ks CVE-2022-23502 GHSA-mgj2-q8wp-29rr
Affected version: >=10.0.0,<10.4.33|>=11.0.0,<11.5.20|>=12.0.0,<12.1.1
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] TYPO3-CORE-SA-2022-013: Weak Authentication in Frontend Login
PKSA-sy8t-czj6-2rjr CVE-2022-23501 GHSA-jfp7-79g7-89rf
Affected version: >=10.0.0,<10.4.33|>=11.0.0,<11.5.20|>=12.0.0,<12.1.1
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] TYPO3-CORE-SA-2022-012: Denial of Service in Page Error Handling
PKSA-wh51-qtyw-9mq5 CVE-2022-23500 GHSA-8c28-5mp7-v24h
Affected version: >=10.0.0,<10.4.33|>=11.0.0,<11.5.20
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] TYPO3-CORE-SA-2022-006: Denial of Service in Page Error Handling
PKSA-h28q-88f6-24c1 CVE-2022-36104 GHSA-fffr-7x4x-f98q
Affected version: >=11.0.0,<11.5.16
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] TYPO3-CORE-SA-2022-011: By-passing Cross-Site Scripting Protection in HTML Sanitizer
PKSA-hkkc-nfmp-dqpt CVE-2022-36020 GHSA-47m6-46mj-p235
Affected version: >=10.0.0,<10.4.32|>=11.0.0,<11.5.16
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] TYPO3-CORE-SA-2022-010: Cross-Site Scripting in <f:asset.css> view helper
PKSA-5bjw-symk-fz45 CVE-2022-36108 GHSA-fv2m-9249-qx85
Affected version: >=10.0.0,<10.4.32|>=11.0.0,<11.5.16
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] TYPO3-CORE-SA-2022-009: Stored Cross-Site Scripting via FileDumpController
PKSA-w21x-17n7-44qc CVE-2022-36107 GHSA-9c6w-55cp-5w25
Affected version: >=10.0.0,<10.4.32|>=11.0.0,<11.5.16
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] TYPO3-CORE-SA-2022-008: Missing check for expiration time of password reset token for backend users
PKSA-z12b-qvn6-4p12 CVE-2022-36106 GHSA-5959-4x58-r8c2
Affected version: >=10.0.0,<10.4.32|>=11.0.0,<11.5.16
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] TYPO3-CORE-SA-2022-007: User Enumeration via Response Timing
PKSA-rrh7-bw6s-dw97 CVE-2022-36105 GHSA-m392-235j-9r7r
Affected version: >=10.0.0,<10.4.32|>=11.0.0,<11.5.16
Reported by:
GitHub, FriendsOfPHP/security-advisories