TYPO3 8.7.30
18 January 2020
TYPO3 version 8.7.30 is now available (security release).
What's New in TYPO3 8.7.30
Security
- Avoid insecure deserialization in QueryGenerator & QueryView
- Prevent SQLi in ext:lowlevel QueryGenerator
- Avoid directory traversal on archive extraction
- XSS in file list through file extension
- Avoid XSS by correctly encoding typolink results
- Prevent XSS in EXT:form error message output
- Avoid possible insecure deserialization in Extbase