Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35994
HistoryJun 15, 2022 - 4:51 a.m.

HTML Injection

2022-06-1504:51:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
html injection
typo3/cms
password recovery
vulnerability
sanitization

EPSS

0.001

Percentile

25.1%

typo3/cms is vulnerable to HTML injection. The vulnerability exists due to the lack of sanitization used in the receiverName parameter in PasswordRecovery.html, allowing an attacker to inject and execute malicious html content on the web page.

EPSS

0.001

Percentile

25.1%