Description
Multiple cross-site scripting (XSS) vulnerabilities in the backend in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.
Remediation
References
Related Vulnerabilities
AbanteCart Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-26521)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-3543)
MediaWiki CVE-2019-12467 Vulnerability (CVE-2019-12467)
Chamilo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-23127)