CVE-2012-1608Improper Input Validation in CMS

Severity
5.0MEDIUMNVD
EPSS
0.7%
top 28.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 4
Latest updateMay 17

Description

The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web script or HTML via non printable characters.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Packagisttypo3/cms4.4.04.4.14+2
NVDtypo3/typo337 versions+36

🔴Vulnerability Details

4
GHSA
Typo3 API XSS Vulnerabilities2022-05-17
OSV
Typo3 API XSS Vulnerabilities2022-05-17
CVEList
CVE-2012-1608: The t3lib_div::RemoveXSS API method in TYPO3 42012-09-04
OSV
CVE-2012-1608: The t3lib_div::RemoveXSS API method in TYPO3 42012-09-04
CVE-2012-1608 — Improper Input Validation in Typo3 CMS | cvebase