Reflected cross-site scripting (XSS) In typo3/cms
Description
Typo3 Cross-Site Scripting in Flash component (ELTS) TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to 7.1.0 included a vulnerable external component, which could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 8.7.7 | ||
packagist | 7.2.0, 6.2.39 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4.