CVE-2015-8758

MEDIUM

TYPO3 6.2.x-6.2.15 and 7.x-7.6.0 - Authenticated Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in unspecified frontend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1034484
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/79240

Scores

CVSS v3 5.4
EPSS 0.0022
EPSS Percentile 44.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (27)
typo3/typo3 6.2.0 alpha1 (12 CPE variants)
typo3/typo3 6.2.1
typo3/typo3 6.2.2
typo3/typo3 6.2.3
typo3/typo3 6.2.4
typo3/typo3 6.2.5
typo3/typo3 6.2.6
typo3/typo3 6.2.7
typo3/typo3 6.2.8
typo3/typo3 6.2.9
... and 17 more
Published Jan 08, 2016
Tracked Since Feb 18, 2026