CVE-2010-3659

EUVD-2022-4422
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified parameters to the extension manager, or unspecified parameters to unknown backend forms.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
Affected Products (NVD)
VendorProductVersion
typo3typo3
4.1.0
typo3typo3
4.1.1
typo3typo3
4.1.2
typo3typo3
4.1.3
typo3typo3
4.1.4
typo3typo3
4.1.5
typo3typo3
4.1.6
typo3typo3
4.1.7
typo3typo3
4.1.8
typo3typo3
4.1.9
typo3typo3
4.1.10
typo3typo3
4.1.11
typo3typo3
4.1.12
typo3typo3
4.1.13
typo3typo3
4.2.0
typo3typo3
4.2.1
typo3typo3
4.2.2
typo3typo3
4.2.3
typo3typo3
4.2.4
typo3typo3
4.2.5
typo3typo3
4.2.6
typo3typo3
4.2.7
typo3typo3
4.2.8
typo3typo3
4.2.9
typo3typo3
4.2.10
typo3typo3
4.2.11
typo3typo3
4.2.12
typo3typo3
4.3.0
typo3typo3
4.3.1
typo3typo3
4.3.2
typo3typo3
4.3.3
typo3typo3
4.4.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
typo3-src
hardy
ignored
lucid
ignored
maverick
ignored
natty
not-affected
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected