Description
Cross-site scripting (XSS) vulnerability in the function menu API in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.
Remediation
References
Related Vulnerabilities
WordPress Plugin Cool Timeline (Horizontal & Vertical Timeline) Cross-Site Request Forgery (2.0.2)
MySQL CVE-2017-3460 Vulnerability (CVE-2017-3460)
WordPress Plugin Simple Slideshow Manager Multiple Cross-Site Scripting Vulnerabilities (2.3)
WordPress Plugin Adminer Multiple Cross-Site Scripting Vulnerabilities (1.4.3)
WordPress Plugin Download Shortcode Arbitrary File Disclosure (0.1)