(#Several cross-site scripting vulnerabilities were reported in third-party components of TYPO3.#A remote attacker can exploit them in order to execute arbitrary Javascript or HTML code by inciting their victim into following a specially formed link.##These vulnerabilities are located in:#- caddy: the "paymillToken" POST parameter of the "http://localhost/typo3plugins/plugins/caddy/Resources/Public/JavaScript/e-payment/paymill/api/php/payment.php" page#- WURFL: the "force_ua" GET parameter of the "http://localhost/typo3plugins/plugins/contexts_wurfl/Library/wurfl-dbapi-1.4.4.0/check_wurfl.php" page.##Proofs of concept are available.)