{"id":"GHSA-c8f2-5h29-8j2h","summary":"libconnect Extension for Typo3 Vulnerable to XSS","details":"The libconnect extension before 7.0.8 and 8.x before 8.1.0 for TYPO3 allows XSS.","aliases":["CVE-2022-33157"],"modified":"2024-02-16T08:20:31.598682Z","published":"2022-07-13T00:00:39Z","database_specific":{"github_reviewed_at":"2023-07-11T00:18:37Z","nvd_published_at":"2022-07-12T23:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-33157"},{"type":"WEB","url":"https://github.com/subhh/libconnect/commit/8c582f3f6575f8744bf29f99bc1697ab8b7bd3af"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-ext-sa-2022-010"}],"affected":[{"package":{"name":"subhh/libconnect","ecosystem":"Packagist","purl":"pkg:composer/subhh/libconnect"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.8"}]}],"versions":["6.0.0","6.1.0","7.0.0","7.0.1","7.0.4","7.0.5","7.0.6","7.0.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-c8f2-5h29-8j2h/GHSA-c8f2-5h29-8j2h.json"}},{"package":{"name":"subhh/libconnect","ecosystem":"Packagist","purl":"pkg:composer/subhh/libconnect"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0"},{"fixed":"8.1.0"}]}],"versions":["8.0.0","8.0.1","8.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-c8f2-5h29-8j2h/GHSA-c8f2-5h29-8j2h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}