Description
The page module in TYPO3 before 8.7.11, and 9.1.0, has XSS via $GLOBALS['TYPO3_CONF_VARS']['SYS']['sitename'], as demonstrated by an admin entering a crafted site name during the installation process.
Remediation
References
Related Vulnerabilities
WordPress Plugin Easy Social Icons Cross-Site Scripting (3.1.2)
WebLogic CVE-2020-2884 Vulnerability (CVE-2020-2884)
WordPress Plugin Happy Addons for Elementor Cross-Site Scripting (2.23.0)
MySQL CVE-2019-2812 Vulnerability (CVE-2019-2812)
WordPress 4.8.x Cross-Domain Flash Injection Vulnerability (4.8 - 4.8.4)