Description
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that database fields used as _descriptionColumn_ are vulnerable to cross-site scripting when their content gets previewed. A valid backend user account is needed to exploit this vulnerability. This is fixed in versions 10.4.14, 11.1.1 .
Remediation
References
Related Vulnerabilities
MySQL CVE-2014-4214 Vulnerability (CVE-2014-4214)
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2016-8612)
IBM WebSEAL Incorrect Default Permissions Vulnerability (CVE-2024-35139)
WordPress 3.8.x Multiple Vulnerabilities (3.8 - 3.8.33)
Squid Improper Handling of Exceptional Conditions Vulnerability (CVE-2023-5824)