Web: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-36108

Sept. 13, 2022, 6:15 p.m. |

National Vulnerability Database nist.gov

TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `f:asset.css` view helper is vulnerable to cross-site scripting when user input is passed as variables to the CSS. Update to TYPO3 version 10.4.32 or 11.5.16 that fix the problem. There are no known workarounds for this issue.

cve

Cybersecurity Engineer

@ Apercen Partners LLC | Folsom, CA

IDM Sr. Security Developer

@ The Ohio State University | Columbus, OH, United States

IT Security Engineer

@ Stylitics | New York City

Information Security Engineer

@ VDA Labs | Remote

Information Security Analyst

@ Metropolitan Transportation Commission | San Francisco, CA

IT Security Manager - Stamford or Middletown Location

@ Charles IT | Middletown, Connecticut, United States

Cyber Security Analyst - Sr. Consultant Level

@ Visa | Ashburn, VA, United States

Staff Information Security Engineer

@ ServiceNow | Atlanta, Georgia, United States

Senior Compliance Program Manager

@ Zscaler | San Jose, CA, United States

Supervisor, F&I Trainer and Compliance Financial Services

@ Lucid Motors | Newark, CA

Senior Information Security Analyst

@ RecargaPay | São Paulo, State of São Paulo, Brazil - Remote

IT Security Engineer - Middletown Location

@ Charles IT | Middletown, Connecticut, United States