CVE-2016-4056

Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers to inject arbitrary web script or HTML via the module parameter when creating a bookmark.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
VendorProductVersion
typo3typo3
6.2
typo3typo3
6.2.0:alpha1
typo3typo3
6.2.0:alpha2
typo3typo3
6.2.0:alpha3
typo3typo3
6.2.0:beta1
typo3typo3
6.2.0:beta2
typo3typo3
6.2.0:beta3
typo3typo3
6.2.0:beta4
typo3typo3
6.2.0:beta5
typo3typo3
6.2.0:beta6
typo3typo3
6.2.0:beta7
typo3typo3
6.2.0:rc1
typo3typo3
6.2.0:rc2
typo3typo3
6.2.1
typo3typo3
6.2.2
typo3typo3
6.2.3
typo3typo3
6.2.4
typo3typo3
6.2.5
typo3typo3
6.2.6
typo3typo3
6.2.7
typo3typo3
6.2.8
typo3typo3
6.2.9
typo3typo3
6.2.10
typo3typo3
6.2.10:rc1
typo3typo3
6.2.11
typo3typo3
6.2.12
typo3typo3
6.2.13
typo3typo3
6.2.14
typo3typo3
6.2.15
typo3typo3
6.2.16
typo3typo3
6.2.17
typo3typo3
6.2.18
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
typo3-src
disco
dne
cosmic
dne
bionic
dne
artful
dne
zesty
dne
yakkety
dne
xenial
dne
wily
dne
trusty
dne
precise
ignored