Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the RemoveXSS function.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1806 | Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the RemoveXSS function. |
Github GHSA |
GHSA-q22w-r5qq-v3wf | Typo3 XSS in RemoveXSS function |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T00:16:35.140Z
Reserved: 2011-12-23T00:00:00
Link: CVE-2011-4903
No data.
Status : Modified
Published: 2019-11-06T17:15:11.330
Modified: 2024-11-21T01:33:16.257
Link: CVE-2011-4903
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA