Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-34355

TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript execution, adversaries can still inject malicious HTML markup. Exploiting this vulnerability requires a valid backend user account. TYPO3 version 13.1.1 fixes the problem described.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 56.8%
CVSS Severity
CVSS v3 Score 3.5
Products affected by CVE-2024-34355
  • Typo3 » Typo3 » Version: 13.0.0
    cpe:2.3:a:typo3:typo3:13.0.0
  • Typo3 » Typo3 » Version: 13.0.1
    cpe:2.3:a:typo3:typo3:13.0.1
  • Typo3 » Typo3 » Version: 13.1.0
    cpe:2.3:a:typo3:typo3:13.1.0


Contact Us

Shodan ® - All rights reserved