{"id":"CVE-2012-6147","aliases":[],"url":"https://o3.security/vulnerability/CVE-2012-6147","summary":"Cross-site scripting (XSS) vulnerability in the tree render API (TCA-Tree) in the Backend API in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote…","details":"Cross-site scripting (XSS) vulnerability in the tree render API (TCA-Tree) in the Backend API in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.","published":"2013-07-01T21:55:01.703","modified":"2026-06-16T23:47:54.597","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"http://osvdb.org/87113"},{"type":"ADVISORY","url":"http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-005/"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/06/19/4"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/79967"},{"type":"WEB","url":"http://osvdb.org/87113"},{"type":"ADVISORY","url":"http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-005/"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/06/19/4"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/79967"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-16T23:47:54.597"}}