Vulnerability Description
An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for TYPO3. The extension fails to properly encode user input for output in HTML context. A TYPO3 backend user account is required to exploit the vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pega-Sus | Google For Jobs | < 1.5.1 |
Related Weaknesses (CWE)
References
- https://typo3.org/security/advisory/typo3-ext-sa-2021-015PatchThird Party Advisory
- https://typo3.org/security/advisory/typo3-ext-sa-2021-015PatchThird Party Advisory
FAQ
What is CVE-2021-43561?
CVE-2021-43561 is a vulnerability with a CVSS score of 5.4 (MEDIUM). An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for TYPO3. The extension fails to properly encode user input for output in HTML con...
How severe is CVE-2021-43561?
CVE-2021-43561 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-43561?
Check the references section above for vendor advisories and patch information. Affected products include: Pega-Sus Google For Jobs.