{"id":"GHSA-73wv-rgj7-vjj9","summary":"Aimeos Typo3 extension contains Cross-site Scripting vulnerability","details":"The aimeos (aka Aimeos shop and e-commerce framework) extension before 19.10.12 and 20.x before 20.10.5 for TYPO3 allows Cross-site Scripting (XSS) via a backend user account.","aliases":["CVE-2021-28380"],"modified":"2024-02-16T08:18:47.552327Z","published":"2022-05-24T17:44:38Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-07-10T23:06:27Z","nvd_published_at":"2021-03-16T20:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-28380"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-ext-sa-2021-003"}],"affected":[{"package":{"name":"aimeos/aimeos-typo3","ecosystem":"Packagist","purl":"pkg:composer/aimeos/aimeos-typo3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"19.10.12"}]}],"versions":["16.10.0","16.10.1","16.10.2","16.10.3","16.10.4","16.10.5","16.7.0","16.7.1","16.7.2","17.10.0","17.10.1","17.10.2","17.10.3","17.10.4","17.3.0","17.4.0","17.4.1","17.4.2","17.7.0","17.7.1","17.7.2","18.1.0","18.1.1","18.10.0","18.10.1","18.10.10","18.10.11","18.10.2","18.10.3","18.10.4","18.10.5","18.10.6","18.10.7","18.10.8","18.10.9","18.4.0","18.4.1","18.4.2","18.7.0","18.7.1","18.7.2","18.7.3","19.1.0","19.10.1","19.10.10","19.10.11","19.10.2","19.10.3","19.10.4","19.10.5","19.10.6","19.10.7","19.10.8","19.10.9","19.4.1","19.4.2","19.4.3","19.7.1","19.7.2","19.7.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-73wv-rgj7-vjj9/GHSA-73wv-rgj7-vjj9.json"}},{"package":{"name":"aimeos/aimeos-typo3","ecosystem":"Packagist","purl":"pkg:composer/aimeos/aimeos-typo3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"20.0.0"},{"fixed":"20.10.5"}]}],"versions":["20.01.1","20.10.1","20.10.2","20.10.3","20.10.4","20.4.1","20.4.2","20.4.3","20.7.1","20.7.2","20.7.3","20.7.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-73wv-rgj7-vjj9/GHSA-73wv-rgj7-vjj9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}