SCA: security update for typo3/cms, typo3/cms-core (GHSA-4j77-gg36-9864)

medium Tenable Cloud Security Plugin ID 422202

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In TYPO3 CMS greater than or equal to 9.5.12 and less than 9.5.17, and greater than or equal to 10.2.0 and
less than 10.4.2, it has been discovered that link tags generated by typolink functionality are vulnerable
to cross-site scripting; properties being assigned as HTML attributes have not been parsed correctly. This
has been fixed in 9.5.17 and 10.4.2. (CVE-2020-11065)

See Also

https://github.com/advisories/GHSA-4j77-gg36-9864

Plugin Details

Severity: Medium

ID: 422202

Version: Revision 1.3

Type: Local

Family: SCA Checks

Published: 3/28/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 8.67

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Low

Base Score: 3.5

Temporal Score: 2.6

Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS Score Source: CVE-2020-11065

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/13/2020

Vulnerability Publication Date: 5/13/2020

Reference Information

CVE: CVE-2020-11065

cwe: CWE-79