Weakness Name | Source | |
---|---|---|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |
Metrics | Score | Severity | CVSS Vector | Source |
---|---|---|---|---|
V2 | 3.5 | AV:N/AC:M/Au:S/C:N/I:P/A:N | [email protected] |
Typo3>>Typo3 >> Version To (including) 4.5.40
Typo3>>Typo3 >> Version 6.0
Typo3>>Typo3 >> Version 6.0.1
Typo3>>Typo3 >> Version 6.0.2
Typo3>>Typo3 >> Version 6.0.3
Typo3>>Typo3 >> Version 6.0.4
Typo3>>Typo3 >> Version 6.0.5
Typo3>>Typo3 >> Version 6.0.6
Typo3>>Typo3 >> Version 6.0.7
Typo3>>Typo3 >> Version 6.0.8
Typo3>>Typo3 >> Version 6.0.9
Typo3>>Typo3 >> Version 6.0.10
Typo3>>Typo3 >> Version 6.0.11
Typo3>>Typo3 >> Version 6.0.12
Typo3>>Typo3 >> Version 6.0.13
Typo3>>Typo3 >> Version 6.0.14
Typo3>>Typo3 >> Version 6.1
Typo3>>Typo3 >> Version 6.1.1
Typo3>>Typo3 >> Version 6.1.2
Typo3>>Typo3 >> Version 6.1.3
Typo3>>Typo3 >> Version 6.1.4
Typo3>>Typo3 >> Version 6.1.5
Typo3>>Typo3 >> Version 6.1.6
Typo3>>Typo3 >> Version 6.1.7
Typo3>>Typo3 >> Version 6.1.8
Typo3>>Typo3 >> Version 6.1.9
Typo3>>Typo3 >> Version 6.2
Typo3>>Typo3 >> Version 6.2.0
Typo3>>Typo3 >> Version 6.2.0
Typo3>>Typo3 >> Version 6.2.0
Typo3>>Typo3 >> Version 6.2.1
Typo3>>Typo3 >> Version 6.2.2
Typo3>>Typo3 >> Version 6.2.3
Typo3>>Typo3 >> Version 6.2.4
Typo3>>Typo3 >> Version 6.2.5
Typo3>>Typo3 >> Version 6.2.6
Typo3>>Typo3 >> Version 6.2.7
Typo3>>Typo3 >> Version 6.2.8
Typo3>>Typo3 >> Version 6.2.9
Typo3>>Typo3 >> Version 6.2.10
Typo3>>Typo3 >> Version 6.2.11
Typo3>>Typo3 >> Version 6.2.12
Typo3>>Typo3 >> Version 6.2.13
Typo3>>Typo3 >> Version 6.2.14
Typo3>>Typo3 >> Version 7.0.0
Typo3>>Typo3 >> Version 7.1.0
Typo3>>Typo3 >> Version 7.2.0
Typo3>>Typo3 >> Version 7.3.0