Back to Database
Status published
Medium
CVE-2015-8759
Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote authenticated editors to inject arbitrary web script or HTML via a link field.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-8759
Credits & Attribution
No credits recorded in the NVD database.
References
More from typo3
View All →CVE-2020-8091
svg.swf in TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to...
Medium
4.8
CVE-2019-19850
An issue was discovered in TYPO3 before 8.7.30, 9.x before...
Medium
5.5
CVE-2019-19849
An issue was discovered in TYPO3 before 8.7.30, 9.x before...
High
8.8
CVE-2019-19848
An issue was discovered in TYPO3 before 8.7.30, 9.x before...
Medium
6.8
CVE-2019-12748
TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS....
Medium
6.1
Affected Vendor
typo3
View all reports →Affected Software
typo3
Vulnerable Versions:
6.2, 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.2.14, 6.2.15, 7.0.0, 7.0.2, 7.1.0, 7.2.0, 7.3.0, 7.3.1, 7.4.0, 7.5.0, 7.6.0, 7.6.1
Timeline
Official Publish:
January 8th, 2016
Last Modified:
September 16th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.