Junglewise Threat Intelligence

CVE-2016-4056: TYPO3 CMS stored XSS in Backend bookmark toolbar

CVE-2016-4056 · Severity: medium · CVSS 6.1 · Published 2017-01-23

Technologies: typo3/cms (Packagist), Typo3 Cms-Core. Vendors: Packagist, Typo3.

Executive brief

A security vulnerability exists in the administrative backend of TYPO3, a popular content management system. An attacker can inject malicious scripts into the bookmarking feature, which could lead to unauthorized actions or data theft when an administrator interacts with the affected bookmark. This could compromise the integrity of the website's management interface.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Backend component of TYPO3 CMS versions 6.2.0 through 6.2.18. The root cause is a failure to properly encode incoming data within the bookmark toolbar subcomponent. Specifically, an attacker can manipulate the 'module' parameter during a POST request when creating a bookmark to inject a malicious payload. While the attack requires user interaction (viewing the bookmark), it can be triggered by remote attackers to execute arbitrary JavaScript in the context of a logged-in user's session. The issue is resolved in TYPO3 version 6.2.19.

Affected products

  • TYPO3 TYPO3 CMS 6.2.0 to 6.2.18

Timeline

  • 2016-02-15: disclosed: Bug reported to TYPO3 team
  • 2016-02-23: patched: TYPO3 version 6.2.19 released
  • 2016-02-24: advisory: Public disclosure by Integrity Labs
  • 2017-01-23: advisory: NVD publication date

References

Related threats