{"id":"GHSA-qfr3-29w6-hwpg","summary":"Typo3 Exception Handler XSS","details":"Cross-site scripting (XSS) vulnerability in the Exception Handler in TYPO3 4.4.x before 4.4.15, 4.5.x before 4.5.15, 4.6.x before 4.6.8, and 4.7 allows remote attackers to inject arbitrary web script or HTML via exception messages.","aliases":["CVE-2012-2112"],"modified":"2024-01-12T18:26:36.936187Z","published":"2022-05-17T01:46:40Z","database_specific":{"github_reviewed_at":"2024-01-12T18:01:23Z","nvd_published_at":"2012-08-27T21:55:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-2112"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/74920"},{"type":"WEB","url":"https://web.archive.org/web/20120421201555/http://www.securityfocus.com/bid/53047"},{"type":"WEB","url":"http://lists.typo3.org/pipermail/typo3-announce/2012/000241.html"},{"type":"WEB","url":"http://lists.typo3.org/pipermail/typo3-announce/2012/000242.html"},{"type":"WEB","url":"http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-002"},{"type":"WEB","url":"http://www.debian.org/security/2012/dsa-2455"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/04/17/5"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/04/18/1"}],"affected":[{"package":{"name":"typo3/cms","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.4"},{"fixed":"4.4.15"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qfr3-29w6-hwpg/GHSA-qfr3-29w6-hwpg.json"}},{"package":{"name":"typo3/cms","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.5"},{"fixed":"4.5.15"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qfr3-29w6-hwpg/GHSA-qfr3-29w6-hwpg.json"}},{"package":{"name":"typo3/cms","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.6"},{"fixed":"4.6.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qfr3-29w6-hwpg/GHSA-qfr3-29w6-hwpg.json"}},{"package":{"name":"typo3/cms","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms"},"versions":["4.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qfr3-29w6-hwpg/GHSA-qfr3-29w6-hwpg.json"}}],"schema_version":"1.9.0"}