RULE(RULE ID:316936)

Rule General Information
Release Date: 2017-03-15
Rule Name: WEB-OTHER Typo3 CMS Sanitizelocalurl Cross-site Scripting Vulnerability -1 (CVE-2015-5956)
Severity:
CVE ID:
Rule Protection Details
Description: The sanitizeLocalUrl function in TYPO3 6.x before 6.2.15, 7.x before 7.4.0, 4.5.40, and earlier allows remote authenticated users to bypass the XSS filter and conduct cross-site scripting (XSS) attacks via a base64 encoded data URI.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Solaris, Other Unix, FreeBSD, Linux
Reference: SecurityTrackerID:1033551
Solutions
More advisories have been published on the website, please visit for more suggestions:
https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2015-009/