关键漏洞信息 标题 Cross-Site Scripting in Form Manager Module 严重性 Moderate CVE ID CVE-2024-34356 受影版本 9.0.0-9.5.47, 10.0.0-10.4.44, 11.0.0-11.5.36, 12.0.0-12.4.14, 13.0.0-13.1.0 修复版本 9.5.48, 10.4.45, 11.5.37, 12.4.15, 13.1.1 描述 问题 - The form manager backend module is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to the form module. 解决方案 - Update to TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 that fix the problem described. 贡献者 - Thanks to TYPO3 core & security team member Benjamin Franzke who reported and fixed the issue. 参考 TYPO3-CORE-SA-2024-008 CVSS v3 基本指标 Attack Vector: Network Attack Complexity: Low Privileges Required: Low User Interaction: Required Scope: Changed Confidentiality: Low Integrity: Low Availability: None 弱点 CWE-79