{"id":"GHSA-q9cp-mc96-m4w2","summary":"XML External Entity in Dashboard Widget","details":"### Problem\nIt has been discovered that RSS widgets are susceptible to XML external entity processing.\nThis vulnerability is reasonable, but is theoretical - it was not possible to actually reproduce the vulnerability with current PHP versions of supported and maintained system distributions.\n\nAt least with _libxml2_ version 2.9, the processing of XML external entities is disabled per default - and cannot be exploited. Besides that, a valid backend user account is needed.\n\n### Solution\nUpdate to TYPO3 version 10.4.10 that fixes the problem described.","aliases":["BIT-typo3-2020-26229","CVE-2020-26229"],"modified":"2026-05-07T05:02:32.734991578Z","published":"2020-11-23T21:18:44Z","database_specific":{"cwe_ids":["CWE-611"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2020-11-23T21:16:32Z","nvd_published_at":"2020-11-23T22:15:12Z"},"references":[{"type":"WEB","url":"https://github.com/TYPO3/TYPO3.CMS/security/advisories/GHSA-q9cp-mc96-m4w2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26229"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2020-26229.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2020-26229.yaml"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-core-sa-2020-012"}],"affected":[{"package":{"name":"typo3/cms-core","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0.0"},{"fixed":"10.4.10"}]}],"versions":["v10.0.0","v10.1.0","v10.2.0","v10.2.1","v10.2.2","v10.3.0","v10.4.0","v10.4.1","v10.4.2","v10.4.3","v10.4.4","v10.4.5","v10.4.6","v10.4.7","v10.4.8","v10.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/11/GHSA-q9cp-mc96-m4w2/GHSA-q9cp-mc96-m4w2.json"}},{"package":{"name":"typo3/cms","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0.0"},{"fixed":"10.4.10"}]}],"versions":["v10.0.0","v10.1.0","v10.2.0","v10.2.1","v10.2.2","v10.3.0","v10.4.0","v10.4.1","v10.4.2","v10.4.3","v10.4.4","v10.4.5","v10.4.6","v10.4.7","v10.4.8","v10.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/11/GHSA-q9cp-mc96-m4w2/GHSA-q9cp-mc96-m4w2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L"}]}