Description
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the Extension Manager.
Remediation
References
Related Vulnerabilities
WordPress Plugin Wp Multiple Meta Box SQL Injection (1.0.0)
WordPress Plugin WP Dynamic Keywords Injector Cross-Site Request Forgery (2.3.15)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17307)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-15110)