Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web script or HTML via non printable characters.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TYPO3 ‘t3lib_div::RemoveXSS API’方法输入验证漏洞
Vulnerability Description
Typo3是基于PHP和MySQL数据库的开源内容管理系统(CMS)和内容管理框架(CMF)的领导性品牌之一,是强大的开源解决方案。 TYPO3 4.4.0至4.4.13版本、4.5.0至4.5.13版本、4.6.0至4.6.6版本、4.7版本和6.0版本中的t3lib_div::RemoveXSS API方法中存在漏洞。远程攻击者可利用该漏洞通过非打印字符绕过跨站脚本(XSS)保护机制,并注入任意web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A