CVE-2014-3943
TYPO3 <4.5.34-6.2.3 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allow remote authenticated editors to inject arbitrary web script or HTML via unknown parameters.
References (5)
Scores
EPSS
0.0021
EPSS Percentile
43.0%
Details
CWE
CWE-79
Status
published
Products (50)
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
typo3/typo3
... and 40 more
Published
Jun 03, 2014
Tracked Since
Feb 18, 2026