{"id":"CVE-2023-47125","aliases":["BIT-typo3-2023-47125","GHSA-mm79-jhqm-9j54"],"url":"https://o3.security/vulnerability/CVE-2023-47125","summary":"By-passing Cross-Site Scripting Protection in HTML Sanitizer","details":"> ### CVSS: `CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N/E:F/RL:O/RC:C` (4.4)\n\n### Problem\nDOM processing instructions are not handled correctly. This allows bypassing the cross-site scripting mechanism of [`typo3/html-sanitizer`](https://packagist.org/packages/typo3/html-sanitizer).\n\n### Solution\nUpdate to `typo3/html-sanitizer` versions 1.5.3 or 2.1.4 that fix the problem described.\n\n### Credits\nThanks to Yaniv Nizry and Niels Dossche who reported this issue, and to TYPO3 core & security team member Oliver Hader who fixed the issue.\n\n### References\n* [TYPO3-CORE-SA-2023-007](https://typo3.org/security/advisory/typo3-core-sa-2023-007)\n* [Context & Details at `masterminds/html5`](https://github.com/Masterminds/html5-php/issues/241)","published":"2023-11-14T20:07:56.433Z","modified":"2026-08-27T03:30:32.937169422Z","cvss":{"score":4.7,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00574,"percentile":0.45974,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/html-sanitizer","fixedVersion":"1.5.3"},{"ecosystem":"Packagist","name":"typo3/html-sanitizer","fixedVersion":"2.1.4"}],"fix":{"url":"https://github.com/TYPO3/html-sanitizer/commit/b8f90717251d968c49dc77f8c1e5912e2fbe0dff","label":"TYPO3/html-sanitizer@b8f9071"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/47xxx/CVE-2023-47125.json"},{"type":"ADVISORY","url":"https://github.com/TYPO3/html-sanitizer/security/advisories/GHSA-mm79-jhqm-9j54"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-47125"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-core-sa-2023-007"},{"type":"FIX","url":"https://github.com/TYPO3/html-sanitizer/commit/b8f90717251d968c49dc77f8c1e5912e2fbe0dff"},{"type":"PACKAGE","url":"https://github.com/TYPO3/html-sanitizer"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T03:30:32.937169422Z"}}