Total vulnerabilities in the database
TYPO3 Fluid Engine (package typo3fluid/fluid
) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripting when making use of the ternary conditional operator in templates like {showFullName ? fullName : defaultValue}
. Updated versions of this package are bundled in following TYPO3 (typo3/cms-core
) versions as well: TYPO3 v8.7.25 (using typo3fluid/fluid
v2.5.4) and TYPO3 v9.5.6 (using typo3fluid/fluid
v2.6.1).
Software | From | Fixed in |
---|---|---|
typo3 / fluid_engine | 2.6.0 | 2.6.1 |
typo3 / fluid_engine | 2.5.0 | 2.5.5 |
typo3 / fluid_engine | 2.4.0 | 2.4.1 |
typo3 / fluid_engine | 2.3.0 | 2.3.5 |
typo3 / fluid_engine | 2.2.0 | 2.2.1 |
typo3 / fluid_engine | 2.1.0 | 2.1.4 |
typo3 / fluid_engine | - | 2.0.5 |
typo3 / typo3 | 9.5.6 | 9.5.6.x |
typo3 / typo3 | 8.7.25 | 8.7.25.x |
![]() |
2.0.0 | 2.0.5 |
![]() |
2.1.0 | 2.1.4 |
![]() |
2.2.0 | 2.2.1 |
![]() |
2.3.0 | 2.3.5 |
![]() |
2.4.0 | 2.4.1 |
![]() |
2.5.0 | 2.5.5 |
![]() |
2.6.0 | 2.6.1 |