Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:alex_kellner:powermail:*:*:*:*:*:*:*:*", "matchCriteriaId": "0CEE9042-76F5-402D-B933-5659780A7548", "versionEndIncluding": "1.6.10", "vulnerable": true}, {"criteria": "cpe:2.3:a:alex_kellner:powermail:1.6.0:*:*:*:*:*:*:*", "matchCriteriaId": "97566C8C-A05C-4226-AFB2-BED8F0CA51B9", "vulnerable": true}, {"criteria": "cpe:2.3:a:alex_kellner:powermail:1.6.1:*:*:*:*:*:*:*", "matchCriteriaId": "1BFEF153-A62D-499B-BD7E-11E4F6F7BEF0", "vulnerable": true}, {"criteria": "cpe:2.3:a:alex_kellner:powermail:1.6.2:*:*:*:*:*:*:*", "matchCriteriaId": "1199C635-5A1F-4884-9E1B-26326FCA0C20", "vulnerable": true}, {"criteria": "cpe:2.3:a:alex_kellner:powermail:1.6.3:*:*:*:*:*:*:*", "matchCriteriaId": "4A4E47D2-4A1A-4153-B6CE-6C679DD186BC", "vulnerable": true}, {"criteria": "cpe:2.3:a:alex_kellner:powermail:1.6.5:*:*:*:*:*:*:*", "matchCriteriaId": "FAE4E946-B3CF-44ED-B68B-F74C7BFF67EC", "vulnerable": true}, {"criteria": "cpe:2.3:a:alex_kellner:powermail:1.6.6:*:*:*:*:*:*:*", "matchCriteriaId": "F23EADCC-2791-441A-B971-1AC05AC5604F", "vulnerable": true}, {"criteria": "cpe:2.3:a:alex_kellner:powermail:1.6.7:*:*:*:*:*:*:*", "matchCriteriaId": "A0554C6A-5E57-4D81-BCED-5BCD63E73162", "vulnerable": true}, {"criteria": "cpe:2.3:a:alex_kellner:powermail:1.6.8:*:*:*:*:*:*:*", "matchCriteriaId": "D6959629-9543-4DD5-82D9-027716C07802", "vulnerable": true}, {"criteria": "cpe:2.3:a:alex_kellner:powermail:1.6.9:*:*:*:*:*:*:*", "matchCriteriaId": "26E6D0AB-6B7C-4E3B-8639-A224CE551E0A", "vulnerable": true}], "negate": false, "operator": "OR"}, {"cpeMatch": [{"criteria": "cpe:2.3:a:typo3:typo3:-:*:*:*:*:*:*:*", "matchCriteriaId": "E66C5ABA-7727-4562-A792-5E450098D520", "vulnerable": false}], "negate": false, "operator": "OR"}], "operator": "AND"}], "cveTags": [], "descriptions": [{"lang": "en", "value": "Cross-site scripting (XSS) vulnerability in the HTML export wizard in the backend module in the powermail extension before 1.6.11 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."}, {"lang": "es", "value": "Vulnerabilidad de XSS en el asistente de exportaci\u00f3n HTML en el m\u00f3dulo backend en la extensi\u00f3n powermail anterior a 1.6.11 para TYPO3 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a trav\u00e9s de vectores no especificados."}], "id": "CVE-2014-3948", "lastModified": "2025-04-12T10:46:40.837", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": {"accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "version": "2.0"}, "exploitabilityScore": 8.6, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true}]}, "published": "2014-06-04T14:55:05.403", "references": [{"source": "cve@mitre.org", "url": "http://secunia.com/advisories/58909"}, {"source": "cve@mitre.org", "url": "http://typo3.org/extensions/repository/view/powermail"}, {"source": "cve@mitre.org", "tags": ["Vendor Advisory"], "url": "http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2014-007"}, {"source": "cve@mitre.org", "url": "http://www.openwall.com/lists/oss-security/2014/06/03/3"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/58909"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://typo3.org/extensions/repository/view/powermail"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2014-007"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.openwall.com/lists/oss-security/2014/06/03/3"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-79"}], "source": "nvd@nist.gov", "type": "Primary"}]}