{"id":"CVE-2021-32667","details":"TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When _Page TSconfig_ settings are not properly encoded, corresponding page preview module (_Web\u003eView_) is vulnerable to persistent cross-site scripting. A valid backend user account is needed to exploit this vulnerability. TYPO3 versions 9.5.29, 10.4.18, 11.3.1 contain a patch for this issue.","aliases":["BIT-typo3-2021-32667","GHSA-8mq9-fqv8-59wf"],"modified":"2026-08-27T03:47:40.791740938Z","published":"2021-07-20T15:15:09.913Z","database_specific":{"unresolved_ranges":[{"vendor_product":"typo3:typo3","cpes":["cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.0.0"},{"last_affected":"9.5.287"},{"introduced":"9.0.0"},{"last_affected":"9.5.287"},{"introduced":"9.0.0"},{"last_affected":"9.5.287"}],"source":"CPE_RANGE"}]},"references":[{"type":"ADVISORY","url":"https://github.com/TYPO3/TYPO3.CMS/security/advisories/GHSA-8mq9-fqv8-59wf"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-core-sa-2021-009"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/TYPO3/typo3","events":[{"introduced":"c91b70e450c52d29ffb08115fffbb7832b15a330"},{"last_affected":"fe16eeb92d49edc5e79041dd949bc68cf66dfdce"},{"introduced":"6a5e2d4097ef0a0e3ea955af93cf83810d6fa234"},{"last_affected":"5f11a2c94ea85f0401b0e00ec962368aa312ea1f"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"10.0.0"},{"last_affected":"10.4.17"},{"introduced":"11.0.0"},{"last_affected":"11.3.0"}]}}],"versions":["v11.3.0","v10.4.17","v10.4.16","v11.2.0","v10.4.15","v10.4.14","v11.1.0","v10.4.13","v11.0.0","v10.4.12","v10.4.11","v10.4.10","v10.4.9","v10.4.8","v10.4.7","v10.4.6","v10.4.5","v10.4.4","v10.4.3","v10.4.2","v10.4.1","v10.4.0","v10.3.0","v10.2.0","v10.1.0","v10.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32667.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/typo3/typo3","events":[{"introduced":"c91b70e450c52d29ffb08115fffbb7832b15a330"},{"last_affected":"fe16eeb92d49edc5e79041dd949bc68cf66dfdce"},{"introduced":"6a5e2d4097ef0a0e3ea955af93cf83810d6fa234"},{"last_affected":"5f11a2c94ea85f0401b0e00ec962368aa312ea1f"}],"database_specific":{"cpe":"cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"10.0.0"},{"last_affected":"10.4.17"},{"introduced":"11.0.0"},{"last_affected":"11.3.0"}],"source":"CPE_RANGE"}}],"versions":["v11.3.0","v10.4.17","v10.4.16","v11.2.0","v10.4.15","v10.4.14","v11.1.0","v10.4.13","v11.0.0","v10.4.12","v10.4.11","v10.4.10","v10.4.9","v10.4.8","v10.4.7","v10.4.6","v10.4.5","v10.4.4","v10.4.3","v10.4.2","v10.4.1","v10.4.0","v10.3.0","v10.2.0","v10.1.0","v10.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32667.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}