Commit 2e96dd0
committed
[SECURITY] Encode indexed search results in frontend rendering
Encodes user-submitted content before rendering search results in
the frontend to mitigate cross-site scripting vulnerabilities.
Resolves: #109695
Releases: main, 14.3, 13.4
Change-Id: Icdeb7e841ce503b79086e37743a7e196581bbb14
Security-Bulletin: TYPO3-CORE-SA-2026-010
Security-References: CVE-2026-47348
Reviewed-on: https://review.typo3.org/c/Packages/TYPO3.CMS/+/94407
Tested-by: Oliver Hader <oliver.hader@typo3.org>
Reviewed-by: Oliver Hader <oliver.hader@typo3.org>1 parent 3ffc083 commit 2e96dd0
1 file changed
Lines changed: 2 additions & 1 deletion
Lines changed: 2 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
399 | 399 | | |
400 | 400 | | |
401 | 401 | | |
| 402 | + | |
402 | 403 | | |
403 | 404 | | |
404 | 405 | | |
405 | 406 | | |
406 | 407 | | |
407 | 408 | | |
408 | 409 | | |
409 | | - | |
| 410 | + | |
410 | 411 | | |
411 | 412 | | |
412 | 413 | | |
| |||
0 commit comments