-
CVSS Score
-The vulnerability occurs in bookmark creation where the 'module' parameter is injected into the backend interface without proper output encoding. TYPO3's BookmarkController::saveAction is responsible for processing bookmark creation requests. The advisory specifically mentions the module parameter as the injection vector, and standard TYPO3 backend architecture would route this parameter through the BookmarkController. The high confidence comes from the vulnerability pattern matching controller actions handling unsanitized request parameters that are reflected in UI elements.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| typo3/cms | composer | >= 6.2.0, < 6.2.19 | 6.2.19 |
A Semantic Attack on Google Gemini - Read the Latest Research