Description
Cross-site scripting (XSS) vulnerability in the function menu API in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.
Remediation
References
Related Vulnerabilities
WordPress Plugin Essential Addons for Elementor Cross-Site Scripting (5.0.8)
WordPress Plugin N-Media Website Contact Form with File Upload Arbitrary File Upload (1.3.4)
OpenSSL Improper Input Validation Vulnerability (CVE-2015-0293)
MediaWiki Improper Input Validation Vulnerability (CVE-2020-35477)