Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29813
HistoryMar 24, 2021 - 6:15 a.m.

Cross-site Scripting (XSS)

2021-03-2406:15:48
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
typo3
cross-site scripting
authenticated user
malicious script
descriptioncolumn
previewed.

EPSS

0.001

Percentile

26.2%

typo3/cms-backend is vulnerable to cross-site scripting. An authenticated malicious user is able to inject and execute malicious script via the descriptionColumn when their content gets previewed.

EPSS

0.001

Percentile

26.2%