GHSA-4mm3-xgc2-656r

Suggest an improvement
Source
https://github.com/advisories/GHSA-4mm3-xgc2-656r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4mm3-xgc2-656r/GHSA-4mm3-xgc2-656r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4mm3-xgc2-656r
Aliases
  • CVE-2013-5100
Published
2022-05-17T01:32:35Z
Modified
2025-04-12T03:57:07Z
Severity
  • 1.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U CVSS Calculator
Summary
Static Methods since 2007 (div2007) extension for TYPO3 vulnerable to Cross-site Scripting
Details

Cross-site scripting (XSS) vulnerability in the Static Methods since 2007 (div2007) extension before 0.10.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the t3lib_div::quoteJSvalue function.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-04-12T03:35:34Z",
    "nvd_published_at":  "2013-08-09T22:55:00Z",
    "severity":  "LOW"
}
References

Affected packages

Packagist / jambagecom/div2007

Package

Name
jambagecom/div2007
Purl
pkg:composer/jambagecom/div2007

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.10.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4mm3-xgc2-656r/GHSA-4mm3-xgc2-656r.json"