← Back

CVE-2015-5956

nvd nist
Published: Sep 16, 2015Modified: May 6, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

The sanitizeLocalUrl function in TYPO3 6.x before 6.2.15, 7.x before 7.4.0, 4.5.40, and earlier allows remote authenticated users to bypass the XSS filter and conduct cross-site scripting (XSS) attacks via a base64 encoded data URI, as demonstrated by the (1) returnUrl parameter to show_rechis.php and the (2) redirect_url parameter to index.php.

Affected (48)

Products: Typo3: Typo3
1 product
Typo3
Configuration A
48 vulnerable
Vulnerable SoftwareAffected Versions
Typo3
Up to 4.5.40
Version 6.0.10
Version 6.0.11
Version 6.0.12
Version 6.0.13
Version 6.0.14
Version 6.0.1
Version 6.0.2
Version 6.0.3
Version 6.0.4
Version 6.0.5
Version 6.0.6
Version 6.0.7
Version 6.0.8
Version 6.0.9
Version 6.0
Version 6.1.1
Version 6.1.2
Version 6.1.3
Version 6.1.4
Version 6.1.5
Version 6.1.6
Version 6.1.7
Version 6.1.8
Version 6.1.9
Version 6.1
Version 6.2.0 beta1
Version 6.2.0 beta2
Version 6.2.0 beta3
Version 6.2.10
Version 6.2.11
Version 6.2.12
Version 6.2.13
Version 6.2.14
Version 6.2.1
Version 6.2.2
Version 6.2.3
Version 6.2.4
Version 6.2.5
Version 6.2.6
Version 6.2.7
Version 6.2.8
Version 6.2.9
Version 6.2
Version 7.0.0
Version 7.1.0
Version 7.2.0
Version 7.3.0

Timeline

No history available yet.