Lucene search

K
osvGoogleOSV:GHSA-QMMW-CH2Q-J6XX
HistoryMay 17, 2022 - 1:37 a.m.

Typo3 Backend API XSS Vulnerability

2022-05-1701:37:41
Google
osv.dev
5

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.6%

Cross-site scripting (XSS) vulnerability in the tree render API (TCA-Tree) in the Backend API in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.6%

Related for OSV:GHSA-QMMW-CH2Q-J6XX