CVE-2015-8757

EUVD-2015-8630
Cross-site scripting (XSS) vulnerability in the Extension Manager in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to extension data during an extension installation.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
Affected Products (NVD)
VendorProductVersion
typo3typo3
6.2.0:alpha1
typo3typo3
6.2.0:alpha2
typo3typo3
6.2.0:alpha3
typo3typo3
6.2.0:beta1
typo3typo3
6.2.0:beta2
typo3typo3
6.2.0:beta3
typo3typo3
6.2.0:beta4
typo3typo3
6.2.0:beta5
typo3typo3
6.2.0:beta6
typo3typo3
6.2.0:beta7
typo3typo3
6.2.0:rc1
typo3typo3
6.2.0:rc2
typo3typo3
6.2.1
typo3typo3
6.2.2
typo3typo3
6.2.3
typo3typo3
6.2.4
typo3typo3
6.2.5
typo3typo3
6.2.6
typo3typo3
6.2.7
typo3typo3
6.2.8
typo3typo3
6.2.9
typo3typo3
6.2.10
typo3typo3
6.2.10:rc1
typo3typo3
6.2.11
typo3typo3
6.2.12
typo3typo3
6.2.13
typo3typo3
6.2.14
typo3typo3
6.2.15
typo3typo3
7.0.0
typo3typo3
7.0.1
typo3typo3
7.0.2
typo3typo3
7.1.0
typo3typo3
7.2.0
typo3typo3
7.3.0
typo3typo3
7.3.1
typo3typo3
7.4.0
typo3typo3
7.5.0
typo3typo3
7.6.0
typo3typo3
7.6.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
typo3-src
artful
dne
bionic
dne
cosmic
dne
disco
dne
precise
ignored
trusty
dne
vivid
ignored
wily
dne
xenial
dne
yakkety
dne
zesty
dne