CVE-2021-21340
packagist/typo3/cms
Cross-site Scripting
Database fields used as _descriptionColumn_
are vulnerable to cross-site scripting when their content gets previewed. A valid backend user account is needed to exploit this vulnerability.
All versions starting from 10.0.0 before 10.4.14, all versions starting from 11.0.0 before 11.1.1
Upgrade to versions 10.4.14, 11.1.1 or above.
2021-03-29
source |