Fluid Components TYPO3 extension vulnerable to Cross-Site Scripting
Moderate severity
GitHub Reviewed
Published
Mar 27, 2023
to the GitHub Advisory Database
•
Updated Oct 29, 2024
Description
Published to the GitHub Advisory Database
Mar 27, 2023
Reviewed
Mar 27, 2023
Published by the National Vulnerability Database
Dec 12, 2023
Last updated
Oct 29, 2024
All versions of Fluid Components before 3.5.0 were susceptible to Cross-Site Scripting. Version 3.5.0 of the extension fixes this issue. Due to the nature of the problem, some changes in your project's Fluid templates might be necessary to prevent unwanted double-escaping of HTML markup.
References