CVE-2012-6148

EPSS 0.22%

Typo3 Function Menu API XSS Vulnerability

Published: 5/17/2022Modified: 1/12/2024
Also known as:GHSA-rgf6-9q7g-55qg

Description

Cross-site scripting (XSS) vulnerability in the function menu API in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.

Affected packages (1)

References (3)