Description
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the tcemain flash message.
Remediation
References
Related Vulnerabilities
IBM WebSEAL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1805)
IBM WebSEAL Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2020-4661)
WordPress Plugin Gravity Forms Infusionsoft Cross-Site Scripting (1.1.4)
Apache HTTP Server Other Vulnerability (CVE-2010-1452)
WordPress Plugin WP BaiDu Submit Cross-Site Scripting (1.2.1)