GHSA-mwqv-jff6-5v62

Suggest an improvement
Source
https://github.com/advisories/GHSA-mwqv-jff6-5v62
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mwqv-jff6-5v62/GHSA-mwqv-jff6-5v62.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mwqv-jff6-5v62
Aliases
  • CVE-2010-3715
Published
2022-05-17T05:47:13Z
Modified
2024-02-08T00:26:46.639114Z
Summary
TYPO3 cross-site scripting (XSS) vulnerability in the RemoveXSS function and the backend
Details

Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the RemoveXSS function, and allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (2) the backend.

Database specific
{
    "nvd_published_at": "2010-10-25T20:01:00Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-02-08T00:03:06Z"
}
References

Affected packages

Packagist / typo3/cms-backend

Package

Name
typo3/cms-backend
Purl
pkg:composer/typo3/cms-backend

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Fixed
4.2.15

Packagist / typo3/cms-backend

Package

Name
typo3/cms-backend
Purl
pkg:composer/typo3/cms-backend

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
4.3.7

Packagist / typo3/cms-backend

Package

Name
typo3/cms-backend
Purl
pkg:composer/typo3/cms-backend

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.4.0
Fixed
4.4.4