CVE-2010-3659
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified…
Does this matter?
Lower severity and a low EPSS score (1.28%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified parameters to the extension manager, or unspecified parameters to unknown backend forms.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.28% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- typo3/typo3
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2010/09/28/8Mailing List
- http://www.openwall.com/lists/oss-security/2014/02/12/8Mailing List
- http://www.securityfocus.com/bid/42029Third Party Advisory, VDB Entry
- https://security-tracker.debian.org/tracker/CVE-2010-3659/Third Party Advisory
- https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-sa-2010-012/Vendor Advisory
- http://www.openwall.com/lists/oss-security/2010/09/28/8Mailing List
- http://www.openwall.com/lists/oss-security/2014/02/12/8Mailing List
- http://www.securityfocus.com/bid/42029Third Party Advisory, VDB Entry
- https://security-tracker.debian.org/tracker/CVE-2010-3659/Third Party Advisory
- https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-sa-2010-012/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.