CVE-2020-26229

LOW3.7EPSS 0.27%

XML External Entity in Dashboard Widget

發布日:2020/11/23修改日:2026/3/13
也稱為:GHSA-q9cp-mc96-m4w2BIT-typo3-2020-26229

描述

### Problem It has been discovered that RSS widgets are susceptible to XML external entity processing. This vulnerability is reasonable, but is theoretical - it was not possible to actually reproduce the vulnerability with current PHP versions of supported and maintained system distributions. At least with _libxml2_ version 2.9, the processing of XML external entities is disabled per default - and cannot be exploited. Besides that, a valid backend user account is needed. ### Solution Update to TYPO3 version 10.4.10 that fixes the problem described.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1LOW3.7CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L

參考連結(5)