VulnerabilityModified
CVE-2012-1606
Multiple cross-site scripting (XSS) vulnerabilities in the Backend component in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allow remote authenticated backend users to inject arbitrary web script or HTML via…
LOW 3.5EPSS 1.61%
Does this matter?
Lower severity and a low EPSS score (1.61%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Backend component in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
- EPSS
- 1.61% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- typo3/typo3
- Source
- secalert@redhat.com
References
- http://osvdb.org/80760
- http://secunia.com/advisories/48622Vendor Advisory
- http://secunia.com/advisories/48647Vendor Advisory
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-001/Vendor Advisory
- http://www.debian.org/security/2012/dsa-2445
- http://www.openwall.com/lists/oss-security/2012/03/30/4
- http://www.securityfocus.com/bid/52771
- http://osvdb.org/80760
- http://secunia.com/advisories/48622Vendor Advisory
- http://secunia.com/advisories/48647Vendor Advisory
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-001/Vendor Advisory
- http://www.debian.org/security/2012/dsa-2445
- http://www.openwall.com/lists/oss-security/2012/03/30/4
- http://www.securityfocus.com/bid/52771
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.