The mm_forum extension through 1.9.5 for TYPO3 allows XSS that can be exploited via CSRF.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15516
Reference (s):
- https://typo3.org/security/advisory/typo3-ext-sa-2020-013
- https://typo3.org/help/security-advisories

