Medium severity4.8NVD Advisory· Published Apr 8, 2018· Updated Jun 17, 2026
CVE-2018-6905
CVE-2018-6905
Description
The page module in TYPO3 before 8.7.11, and 9.1.0, has XSS via $GLOBALS['TYPO3_CONF_VARS']['SYS']['sitename'], as demonstrated by an admin entering a crafted site name during the installation process.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
typo3/cmsPackagist | < 9.2.0 | 9.2.0 |
Affected products
2Patches
Vulnerability mechanics
References
5- forge.typo3.org/issues/84191nvdPatchVendor AdvisoryWEB
- www.securitytracker.com/id/1040755nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-3w22-wrwx-2r75ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-6905ghsaADVISORY
- github.com/TYPO3/typo3/commit/d2c0ea7db3b31a796a82f9d39f77f9983beb7c35ghsaWEB
News mentions
0No linked articles in our index yet.