Description
Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers to inject arbitrary web script or HTML via the module parameter when creating a bookmark.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP-Ban Security Bypass (1.63)
Apache Tomcat Improper Input Validation Vulnerability (CVE-2012-3544)
WordPress Plugin LiveChat-WP live chat Cross-Site Scripting (3.7.3)
TYPO3 Use of Insufficiently Random Values Vulnerability (CVE-2010-3666)
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-0328)