Mon. 15th December, 2014
It has been discovered that the extension "Drag Drop Mass Upload" (ameos_dragndropupload) is susceptible to Cross-Site Scripting, Cross-Site Request Forgery and Improper Access Control.
This is a companion discussion topic for the original entry at https://typo3.org/article/typo3-ext-sa-2014-019