CVE-2012-1070
TYPO3 irfaq <1.1.4 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Modern FAQ (irfaq) extension 1.1.2 and other versions before 1.1.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the "return url parameter."
References (4)
Scores
EPSS
0.0031
EPSS Percentile
53.8%
Classification
CWE
CWE-79
Status
published
Affected Products (6)
netcreators/irfaq
netcreators/irfaq
netcreators/irfaq
netcreators/irfaq
netcreators/irfaq
n/a/n/a
Timeline
Published
Feb 14, 2012
Tracked Since
Feb 18, 2026