Junglewise Threat Intelligence

TYPO3 cms-fluid cross-site scripting in Fluid ViewHelpers

Severity: medium · CVSS 6.1 · Published 2024-05-30

Vendors: Typo3.

Executive brief

TYPO3, a popular content management system, contains a vulnerability in its Fluid templating engine. This flaw allows attackers to inject malicious scripts into web pages viewed by other users. If exploited, this could lead to unauthorized actions being performed in a user's session or the theft of sensitive information like login cookies.

Technical details

A cross-site scripting (XSS) vulnerability exists in the TYPO3 Fluid templating engine (typo3/cms-fluid). The root cause is the improper neutralization of user-controllable input within built-in Fluid ViewHelpers during web page generation. A remote, unauthenticated attacker can exploit this by providing malicious input that is subsequently rendered by a vulnerable template. Successful exploitation requires user interaction (a victim viewing the affected page) and allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session. The issue is addressed in versions 8.7.23 and 9.5.4.

Affected products

  • TYPO3 cms-fluid >= 8.0.0, < 8.7.23
  • TYPO3 cms-fluid >= 9.0.0, < 9.5.4

Timeline

  • 2019-01-22: advisory: Original TYPO3 security advisory date
  • 2024-05-30: disclosed: GitHub Advisory published
  • 2024-05-30: patched: GitHub Advisory marked as reviewed/patched

References