{"id":"GHSA-3mqf-fwc6-vwqw","summary":"TYPO3 Cross-site scripting (XSS) vulnerability in the FORM content object ","details":"Cross-site scripting (XSS) vulnerability in the FORM content object in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.","aliases":["CVE-2010-5098"],"modified":"2024-02-08T00:11:46.875927Z","published":"2022-05-17T01:55:58Z","database_specific":{"github_reviewed_at":"2024-02-07T23:40:36Z","nvd_published_at":"2012-05-21T20:55:00Z","cwe_ids":["CWE-79"],"severity":"LOW","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2010-5098"},{"type":"WEB","url":"https://github.com/TYPO3/typo3/commit/3c5d15233ca765fabeac21f0600d831595d31cd8"},{"type":"WEB","url":"https://github.com/TYPO3/typo3/commit/4e8bd7a15681c0683196984e871f60f0646ea2b6"},{"type":"WEB","url":"https://github.com/TYPO3/typo3/commit/6d17fe7cef30b09a65e0c2d54f8871ec3ddfc67e"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64179"},{"type":"PACKAGE","url":"https://github.com/TYPO3-CMS/frontend"},{"type":"WEB","url":"https://web.archive.org/web/20101229020821/http://secunia.com/advisories/35770"},{"type":"WEB","url":"https://web.archive.org/web/20111025222220/http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-022"},{"type":"WEB","url":"https://web.archive.org/web/20111223211753/http://www.securityfocus.com/bid/45470"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/01/13/2"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/05/10/7"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/05/11/3"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/05/12/5"}],"affected":[{"package":{"name":"typo3/cms-frontend","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms-frontend"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.2.0"},{"fixed":"4.2.16"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-3mqf-fwc6-vwqw/GHSA-3mqf-fwc6-vwqw.json"}},{"package":{"name":"typo3/cms-frontend","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms-frontend"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.4.0"},{"fixed":"4.4.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-3mqf-fwc6-vwqw/GHSA-3mqf-fwc6-vwqw.json"}},{"package":{"name":"typo3/cms-frontend","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms-frontend"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.3.0"},{"fixed":"4.3.9"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-3mqf-fwc6-vwqw/GHSA-3mqf-fwc6-vwqw.json"}}],"schema_version":"1.9.0"}