Medium severity4.7NVD Advisory· Published Jul 25, 2023· Updated Jun 17, 2026
CVE-2023-38500
CVE-2023-38500
Description
TYPO3 HTML Sanitizer is an HTML sanitizer, written in PHP, aiming to provide cross-site-scripting-safe markup based on explicitly allowed tags, attributes and values. Starting in version 1.0.0 and prior to versions 1.5.1 and 2.1.2, due to an encoding issue in the serialization layer, malicious markup nested in a noscript element was not encoded correctly. noscript is disabled in the default configuration, but might have been enabled in custom scenarios. This allows bypassing the cross-site scripting mechanism of TYPO3 HTML Sanitizer. Versions 1.5.1 and 2.1.2 fix the problem.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
typo3/html-sanitizerPackagist | >= 1.0.0, < 1.5.1 | 1.5.1 |
typo3/html-sanitizerPackagist | >= 2.0.0, < 2.1.2 | 2.1.2 |
Affected products
3cpe:2.3:a:typo3:html_sanitizer:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:typo3:html_sanitizer:*:*:*:*:*:*:*:*range: >=1.0.0,<1.5.1
- (no CPE)range: >= 1.0.0, < 1.5.1
Patches
Vulnerability mechanics
References
5- github.com/TYPO3/html-sanitizer/commit/e3026f589fef0be8c3574ee3f0a0bfbe33d7ebdbnvdPatchWEB
- github.com/TYPO3/html-sanitizer/security/advisories/GHSA-59jf-3q9v-rh6gnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-59jf-3q9v-rh6gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-38500ghsaADVISORY
- typo3.org/security/advisory/typo3-core-sa-2023-002nvdVendor AdvisoryWEB
News mentions
0No linked articles in our index yet.