{"id":"GHSA-qffc-gwpp-m2xr","aliases":[],"url":"https://o3.security/vulnerability/GHSA-qffc-gwpp-m2xr","summary":"XML External Entity (XXE) Processing in TYPO3 Core","details":"All XML processing within the TYPO3 CMS are vulnerable to XEE processing. This can lead to load internal and/or external (file) content within an XML structure. Furthermore it is possible to inject arbitrary files for an XML Denial of Service attack. For more information on that topic see https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing.","published":"2024-06-04T14:47:00Z","modified":"2024-12-01T05:44:07.735721Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"6.2.19"},{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"7.6.4"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/2016-02-23-1.yaml"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-core-sa-2016-005"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-01T05:44:07.735721Z"}}