svg.swf in TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to 7.1.0 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system. This may be at a contrib/websvg/svg.swf pathname.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| typo3/cms(Packagist) | 7.0.0 | 7.2.0 | N/A |
| typo3/cms(Packagist) | 6.2.0 | 6.2.39 | N/A |
CVSS Metrics