Vulnerable Systems:
* TYPO3 Powermail versions 1.6.6 and prior
An attacker may exploit the HTML-injection issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, control how the site is displayed, and launch other attacks.
Vendor Status:
Currently we are not aware of any vendor-supplied patches.
Disclosure Timeline:
Initial Release : Jun 08 2012