Skip to main navigation Skip to main content Skip to page footer

Multiple vulnerabilities in TYPO3 CMS

28 February 2017 ยท Nicole Cordes
Dear TYPO3 users,

It has been discovered that TYPO3 CMS is susceptible to Authentication Bypass and Cross-Site Scripting.

For details on the issues please read the accordant advisories:

TYPO3-CORE-SA-2017-002: Authentication Bypass in TYPO3 Frontend
https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2017-002/
	
TYPO3-CORE-SA-2017-003: Cross-Site Scripting in TYPO3 CMS 
https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2017-003/


In general the TYPO3 Security Team recommends to read the following pages:

The TYPO3 Security Guide:
https://docs.typo3.org/typo3cms/SecurityGuide/

Make sure you are subscribed to the TYPO3 Announce List:
http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce

See all TYPO3 security advisories:
https://typo3.org/teams/security/security-bulletins/


Regards,

Nicole Cordes
Member of the TYPO3 Security Team

--
TYPO3 Security Team homepage: https://typo3.org/teams/security/

E-Mail: security@typo3.org