VYPR
Medium severity6.1NVD Advisory· Published Jan 27, 2020· Updated Jun 17, 2026

CVE-2020-8091

CVE-2020-8091

Description

svg.swf in TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to 7.1.0 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system. This may be at a contrib/websvg/svg.swf pathname.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
typo3/cmsPackagist
>= 7.0.0, < 7.2.07.2.0
typo3/cmsPackagist
>= 6.2.0, < 6.2.396.2.39

Affected products

5
  • TYPO3/Typo32 versions
    cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*range: >=7.0.0,<=7.1.0
    • cpe:2.3:a:typo3:typo3:*:*:*:*:elts:*:*:*range: >=6.2,<6.2.39
  • TYPO3/TYPO3 webSVG contribdescription
  • osv-coords2 versions
    >= 6.2.0, < 6.2.39+ 1 more
    • (no CPE)range: >= 6.2.0, < 6.2.39
    • (no CPE)range: >= 7.0.0, < 7.2.0

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.