The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web script or HTML via non printable characters.
2012-09-04T20:55:01.357
2025-04-11T00:51:21.963
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | typo3 | typo3 | 4.4.0 | Yes |
Application | typo3 | typo3 | 4.4.1 | Yes |
Application | typo3 | typo3 | 4.4.2 | Yes |
Application | typo3 | typo3 | 4.4.3 | Yes |
Application | typo3 | typo3 | 4.4.4 | Yes |
Application | typo3 | typo3 | 4.4.5 | Yes |
Application | typo3 | typo3 | 4.4.6 | Yes |
Application | typo3 | typo3 | 4.4.7 | Yes |
Application | typo3 | typo3 | 4.4.8 | Yes |
Application | typo3 | typo3 | 4.4.9 | Yes |
Application | typo3 | typo3 | 4.4.10 | Yes |
Application | typo3 | typo3 | 4.4.11 | Yes |
Application | typo3 | typo3 | 4.4.12 | Yes |
Application | typo3 | typo3 | 4.4.13 | Yes |
Application | typo3 | typo3 | 4.5.0 | Yes |
Application | typo3 | typo3 | 4.5.1 | Yes |
Application | typo3 | typo3 | 4.5.2 | Yes |
Application | typo3 | typo3 | 4.5.3 | Yes |
Application | typo3 | typo3 | 4.5.4 | Yes |
Application | typo3 | typo3 | 4.5.5 | Yes |
Application | typo3 | typo3 | 4.5.6 | Yes |
Application | typo3 | typo3 | 4.5.7 | Yes |
Application | typo3 | typo3 | 4.5.8 | Yes |
Application | typo3 | typo3 | 4.5.9 | Yes |
Application | typo3 | typo3 | 4.5.10 | Yes |
Application | typo3 | typo3 | 4.5.11 | Yes |
Application | typo3 | typo3 | 4.5.12 | Yes |
Application | typo3 | typo3 | 4.5.13 | Yes |
Application | typo3 | typo3 | 4.6.0 | Yes |
Application | typo3 | typo3 | 4.6.1 | Yes |
Application | typo3 | typo3 | 4.6.2 | Yes |
Application | typo3 | typo3 | 4.6.3 | Yes |
Application | typo3 | typo3 | 4.6.4 | Yes |
Application | typo3 | typo3 | 4.6.5 | Yes |
Application | typo3 | typo3 | 4.6.6 | Yes |
Application | typo3 | typo3 | 4.7 | Yes |
Application | typo3 | typo3 | 6.0 | Yes |