1 results (0.002 seconds)

CVSS: 3.5EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in the News Pack extension 0.1.0 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en la extensión News Pack 0.1.0 y anteriores para TYPO3 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2014-010 http://www.securityfocus.com/bid/69567 https://exchange.xforce.ibmcloud.com/vulnerabilities/95708 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •