GHSA-rrh3-cgmx-w62f

Suggest an improvement
Source
https://github.com/advisories/GHSA-rrh3-cgmx-w62f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-rrh3-cgmx-w62f/GHSA-rrh3-cgmx-w62f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rrh3-cgmx-w62f
Aliases
  • CVE-2025-30083
Published
2025-03-19T01:37:06Z
Modified
2025-03-19T01:42:25.449027Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:F/RL:O/RC:C CVSS Calculator
Summary
Additional TCA Allows Cross-Site Scripting (XSS)
Details

A cross-site scripting (XSS) vulnerability has been discovered in the Additional TCA extension. This vulnerabily is exploitable by a logged in backend user utilizing the TYPO3 backend user interface. This user can create output in the HTML context by exploiting improperly encoded user input. Updates 1.15.17 and 1.16.9 are available for download.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2025-03-19T01:37:06Z"
}
References

Affected packages

Packagist / codingms/additional-tca

Package

Name
codingms/additional-tca
Purl
pkg:composer/codingms/additional-tca

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.16.0
Fixed
1.16.9

Affected versions

1.*

1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8

Packagist / codingms/additional-tca

Package

Name
codingms/additional-tca
Purl
pkg:composer/codingms/additional-tca

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.7.0
Fixed
1.15.17

Affected versions

1.*

1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.9.0
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.14.8
1.14.9
1.14.10
1.14.11
1.14.12
1.14.13
1.14.14
1.14.15
1.14.16
1.15.0
1.15.1
1.15.2
1.15.3
1.15.4
1.15.5
1.15.6
1.15.7
1.15.8
1.15.9
1.15.10
1.15.11
1.15.12
1.15.13
1.15.14
1.15.15
1.15.16