Description
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that content elements of type _menu_ are vulnerable to cross-site scripting when their referenced items get previewed in the page module. A valid backend user account is needed to exploit this vulnerability. This is fixed in versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1.
Remediation
References
Related Vulnerabilities
Moodle Incorrect Default Permissions Vulnerability (CVE-2012-1157)
WordPress Plugin WP Vault Local File Inclusion (0.8.6.6)
OpenSSL Possible denial of service attack Vulnerability (CVE-2020-1971)
Jetty Improper Neutralization of Quoting Syntax Vulnerability (CVE-2023-36479)
WordPress Plugin BackUpWordPress Remote File Inclusion (0.4.2b)