← Back

CVE-2020-15241

nvd nist
Published: Oct 8, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripting when making use of the ternary conditional operator in templates like `{showFullName ? fullName : defaultValue}`. Updated versions of this package are bundled in following TYPO3 (`typo3/cms-core`) versions as well: TYPO3 v8.7.25 (using `typo3fluid/fluid` v2.5.4) and TYPO3 v9.5.6 (using `typo3fluid/fluid` v2.6.1).

Affected (9)

2 products
Fluid Engine
Typo3
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Typo3
Before 2.0.5
From 2.1.0 to 2.1.4
From 2.2.0 to 2.2.1
From 2.3.0 to 2.3.5
From 2.4.0 to 2.4.1
From 2.5.0 to 2.5.5
From 2.6.0 to 2.6.1
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Typo3
Version 8.7.25
Version 9.5.6

References (6)

Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
ExploitThird Party Advisory
Source: security-advisories@github.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.