{"id":"GHSA-76r3-m635-p3vc","summary":"TYPO3 Cross-Site Scripting in Language Pack Handling","details":"Failing to properly encode information from external sources, language pack handling in the install tool is vulnerable to cross-site scripting.\n\n","modified":"2024-12-05T05:41:20.896204Z","published":"2024-05-30T16:14:41Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-05-30T16:14:41Z","nvd_published_at":null,"cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/2019-01-22-8.yaml"},{"type":"PACKAGE","url":"https://github.com/TYPO3-CMS/core"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-core-sa-2019-004"}],"affected":[{"package":{"name":"typo3/cms-core","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.2.0"},{"fixed":"9.5.4"}]}],"versions":["v9.2.0","v9.2.1","v9.3.0","v9.3.1","v9.3.2","v9.3.3","v9.4.0","v9.5.0","v9.5.1","v9.5.2","v9.5.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-76r3-m635-p3vc/GHSA-76r3-m635-p3vc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}