CVE-2021-36793
13.08.2021, 17:15
The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitive Information Disclosure because a session identifier is unsafely present in HTML output.Enginsight
Vendor | Product | Version |
---|---|---|
routes_project | routes | 𝑥 < 2.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration