CVE-2010-3715
Typo3 < 4.2.15 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the RemoveXSS function, and allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (2) the backend.
Scores
EPSS
0.0030
EPSS Percentile
52.6%
Classification
CWE
CWE-79
Status
draft
Affected Products (27)
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
... and 12 more
Timeline
Published
Oct 25, 2010
Tracked Since
Feb 18, 2026