{"id":"CVE-2015-8760","aliases":[],"url":"https://o3.security/vulnerability/CVE-2015-8760","summary":"TYPO3 allows remote attackers to embed Flash videos from external domain","details":"The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka \"Cross-Site Flashing.\"","published":"2022-05-17T03:59:51Z","modified":"2025-04-14T20:42:19.620691Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.01434,"percentile":0.70568,"asOf":"2026-08-09"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"6.2.16"}],"fix":{"url":"https://github.com/TYPO3/typo3/commit/29ae05c04cb48d4031d323f17d8f2b68b27af353","label":"TYPO3/typo3@29ae05c"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-8760"},{"type":"WEB","url":"https://github.com/TYPO3/typo3/commit/29ae05c04cb48d4031d323f17d8f2b68b27af353"},{"type":"PACKAGE","url":"https://github.com/TYPO3/typo3"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-core-sa-2015-014"},{"type":"WEB","url":"https://web.archive.org/web/20160621232021/http://www.securityfocus.com/bid/79210"},{"type":"WEB","url":"https://web.archive.org/web/20161012163613/http://www.securitytracker.com/id/1034485"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-04-14T20:42:19.620691Z"}}