{"id":"CVE-2024-34357","aliases":["GHSA-hw6c-6gwq-3m3m"],"url":"https://o3.security/vulnerability/CVE-2024-34357","summary":"TYPO3 vulnerable to Cross-Site Scripting in ShowImageController","details":"### Problem\nFailing to properly encode user-controlled values in file entities, the `ShowImageController` (_eID tx_cms_showpic_) is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to file entities.\n\n### Solution\nUpdate to TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 that fix the problem described.\n\n### Credits\nThanks to TYPO3 security team member Torben Hansen who reported this issue and to TYPO3 core & security team member Oliver Hader who fixed the issue.\n\n### References\n* [TYPO3-CORE-SA-2024-009](https://typo3.org/security/advisory/typo3-core-sa-2024-009)\n","published":"2024-05-14T14:13:11.860Z","modified":"2026-08-27T03:31:06.453770736Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"9.5.48"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"10.4.45"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"11.5.37"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"12.4.15"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"13.1.1"}],"fix":{"url":"https://github.com/TYPO3/typo3/commit/376474904f6b9a54dc1b785a2e45277cbd13b0d7","label":"TYPO3/typo3@3764749"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/34xxx/CVE-2024-34357.json"},{"type":"ADVISORY","url":"https://github.com/TYPO3/typo3/security/advisories/GHSA-hw6c-6gwq-3m3m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34357"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-core-sa-2024-009"},{"type":"FIX","url":"https://github.com/TYPO3/typo3/commit/376474904f6b9a54dc1b785a2e45277cbd13b0d7"},{"type":"FIX","url":"https://github.com/TYPO3/typo3/commit/b31d05d1da3eeaeead2d19eb43b1c3f9c88e15ee"},{"type":"FIX","url":"https://github.com/TYPO3/typo3/commit/d774642381354d3bf5095a5a26e18acd2767f0b1"},{"type":"PACKAGE","url":"https://github.com/TYPO3/typo3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T03:31:06.453770736Z"}}