CVE-2012-3530Cross-site Scripting in CMS

Severity
4.3MEDIUMNVD
EPSS
0.6%
top 31.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 5
Latest updateMay 17

Description

Incomplete blacklist vulnerability in the t3lib_div::quoteJSvalue API function in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote attackers to conduct cross-site scripting (XSS) attacks via certain HTML5 JavaScript events.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Packagisttypo3/cms4.54.5.19+2
NVDtypo3/typo338 versions+37

🔴Vulnerability Details

3
OSV
Typo3 API XSS Vulnerability2022-05-17
GHSA
Typo3 API XSS Vulnerability2022-05-17
CVEList
CVE-2012-3530: Incomplete blacklist vulnerability in the t3lib_div::quoteJSvalue API function in TYPO3 42012-09-05
CVE-2012-3530 — Cross-site Scripting in Typo3 CMS | cvebase