CVE-2021-21358
packagist/typo3/cms
Cross-site Scripting
The Form Designer backend module of the Form Framework is vulnerable to cross-site scripting. A valid backend user account with access to the form module is needed to exploit this vulnerability.
All versions starting from 10.2.0 before 10.4.14, all versions starting from 11.0.0 before 11.1.1
Upgrade to versions 10.4.14, 11.1.1 or above.
2021-03-29
source |