Description
Cross-site scripting (XSS) vulnerability in the Exception Handler in TYPO3 4.4.x before 4.4.15, 4.5.x before 4.5.15, 4.6.x before 4.6.8, and 4.7 allows remote attackers to inject arbitrary web script or HTML via exception messages.
Remediation
References
Related Vulnerabilities
WordPress Plugin CAC Featured Content TimThumb Arbitrary File Upload (0.8)
WordPress Plugin 360 Product Rotation Cross-Site Scripting (1.4.7)
WordPress Plugin Weather for us-animated weather widget Crypto Mining (1.8)
WordPress Plugin JetWidgets for Elementor and WooCommerce Local File Inclusion (1.1.7)