VYPR
Moderate severityNVD Advisory· Published Sep 5, 2012· Updated Jun 16, 2026

CVE-2012-3530

CVE-2012-3530

Description

Incomplete blacklist vulnerability in the t3lib_div::quoteJSvalue API function in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote attackers to conduct cross-site scripting (XSS) attacks via certain HTML5 JavaScript events.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
typo3/cmsPackagist
>= 4.5, < 4.5.194.5.19
typo3/cmsPackagist
>= 4.6, < 4.6.124.6.12
typo3/cmsPackagist
>= 4.7, < 4.7.44.7.4

Affected products

39
  • TYPO3/Typo338 versions
    cpe:2.3:a:typo3:typo3:4.5:*:*:*:*:*:*:*+ 37 more
    • cpe:2.3:a:typo3:typo3:4.5:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.10:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.11:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.12:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.13:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.14:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.15:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.16:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.17:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.18:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.5:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.6:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.7:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.8:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.5.9:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.10:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.11:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.4:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.5:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.6:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.7:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.8:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.6.9:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.7.3:*:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 4.5, < 4.5.19

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.