Description
svg.swf in TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to 7.1.0 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system. This may be at a contrib/websvg/svg.swf pathname.
Remediation
References
Related Vulnerabilities
WordPress Plugin Chamber Dashboard Business Directory Cross-Site Scripting (3.2.8)
AngularJS Improper Input Validation Vulnerability (CVE-2019-10768)
Roundcube Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-12626)
MediaWiki Missing Authentication for Critical Function Vulnerability (CVE-2019-12468)