Lucene search

K
osvGoogleOSV:GHSA-GVXV-P9RV-GMCG
HistoryJun 17, 2022 - 9:46 p.m.

brotkrueml/typo3-matomo-integration vulnerable to Cross-Site Scripting

2022-06-1721:46:28
Google
osv.dev
15
cross-site scripting
html context
typo3
matomo
backend user account

EPSS

0.001

Percentile

31.3%

The extension fails to properly encode user input for output in HTML context. A TYPO3 backend user account is required to exploit the vulnerability.

EPSS

0.001

Percentile

31.3%