(:A cross-site scripting vulnerability was reported in TYPO3 Formhandler extension.:A remote attacker could exploit it by enticing their victim into following a specially crafted link in order to execute arbitrary JavaScript or HTML code.::This vulnerability is located in the ransom auth ID, when specially encoded, allows bypass of the "removeXSS()" function (Classes/Interceptor/RemoveXSS.php).::Proofs of concept are available.)