{"id":"GHSA-vc74-c4m6-9979","summary":"TYPO3 Flow Cross-site scripting (XSS) vulnerability","details":"Cross-site scripting (XSS) vulnerability in the errorAction method in the ActionController base class in TYPO3 Flow (formerly FLOW3) 1.1.x before 1.1.1 and 2.0.x before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message.","aliases":["CVE-2013-7082"],"modified":"2024-12-03T06:08:33.389051Z","published":"2022-05-17T01:29:43Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-08-28T23:35:27Z","nvd_published_at":"2013-12-21T00:55:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-7082"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/89614"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/neos/flow/CVE-2013-7082.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/flow/CVE-2013-7082.yaml"},{"type":"WEB","url":"https://www.neos.io/blog/flow-sa-2013-001.html"},{"type":"WEB","url":"http://osvdb.org/100825"},{"type":"WEB","url":"http://secunia.com/advisories/55996"},{"type":"WEB","url":"http://typo3.org/teams/security/security-bulletins/typo3-flow/typo3-flow-sa-2013-001"}],"affected":[{"package":{"name":"neos/flow","ecosystem":"Packagist","purl":"pkg:composer/neos/flow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.1.0"},{"fixed":"1.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-vc74-c4m6-9979/GHSA-vc74-c4m6-9979.json"}},{"package":{"name":"neos/flow","ecosystem":"Packagist","purl":"pkg:composer/neos/flow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.1"}]}],"versions":["2.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-vc74-c4m6-9979/GHSA-vc74-c4m6-9979.json"}},{"package":{"name":"typo3/flow","ecosystem":"Packagist","purl":"pkg:composer/typo3/flow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.1.0"},{"fixed":"1.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-vc74-c4m6-9979/GHSA-vc74-c4m6-9979.json"}},{"package":{"name":"typo3/flow","ecosystem":"Packagist","purl":"pkg:composer/typo3/flow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.1"}]}],"versions":["2.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-vc74-c4m6-9979/GHSA-vc74-c4m6-9979.json"}}],"schema_version":"1.9.0"}