Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers to inject arbitrary web script or HTML via the module parameter when creating a bookmark.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "6.2.0-alpha1"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.0-alpha2"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.0-alpha3"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.0-beta3"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.0-beta4"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.0-beta5"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.0-beta6"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.0-beta7"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.0-rc2"
}
]
}{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "6.2"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.2"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.3"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.4"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.5"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.6"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.7"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.8"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.9"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.10"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.10-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.11"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.12"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.13"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.14"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.15"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.16"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.17"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.18"
}
]
}