GHSA-47m6-46mj-p235

    Dashboard / Vulnerabilities / GHSA-47m6-46mj-p235

    GHSA-47m6-46mj-p235

    Published: 16 Sept 2022Last Modified: 8 Nov 2023

    Summary: TYPO3 HTML Sanitizer Bypasses Cross-Site Scripting Protection

    Details: > ### Meta > * CVSS: `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:F/RL:O/RC:C` (5.7) ### Problem Due to a parsing issue in upstream package [`masterminds/html5`](https://packagist.org/packages/masterminds/html5), malicious markup used in a sequence with special HTML comments cannot be filtered and sanitized. This allows to by-pass the cross-site scripting mechanism of `typo3/html-sanitizer`. ### Solution Update to `typo3/html-sanitizer` versions 1.0.7 or 2.0.16 that fix the problem described. ### Credits Thanks to David Klein who reported this issue, and to TYPO3 security team member Oliver Hader who fixed the issue.

    Affected packages

    Package

    Name: typo3/html-sanitizer

    Purl: pkg:composer/typo3/html-sanitizer

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 1.0.0
    Fixed -1.0.7

    Affected versions

    v1.0.0
    v1.0.1
    v1.0.2
    v1.0.3
    v1.0.4
    v1.0.5
    v1.0.6

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-47m6-46mj-p235 | CVE-DB