Description
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the system extension recycler.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP e-Commerce Shop Styling Remote File Inclusion (1.7.2)
Oracle JRE CVE-2013-0437 Vulnerability (CVE-2013-0437)
PHP Cryptographic Issues Vulnerability (CVE-2012-2143)
Joomla Improper Privilege Management Vulnerability (CVE-2018-11323)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-1184)