CVE-2008-2525: XSS
Published Jun 3, 2008
·Updated
Cross-site scripting (XSS) vulnerability in the Event Database (aka rlmpeventdb) extension before 1.1.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
6 affected components
Typo3 Rlmp Eventdb<=1.1.1
Typo3 Rlmp Eventdb=1.0.1
Typo3 Rlmp Eventdb=1.0.2
Typo3 Rlmp Eventdb=1.0.3
Typo3 Rlmp Eventdb=1.0.4
Typo3 Rlmp Eventdb=1.0.5
Remediation
Event History
Jun 3, 2008
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2525?
The severity of CVE-2008-2525 is classified as moderate due to its ability to execute arbitrary web scripts or HTML.
2
How do I fix CVE-2008-2525?
To fix CVE-2008-2525, upgrade to the Event Database extension version 1.1.2 or later.
3
What software is affected by CVE-2008-2525?
CVE-2008-2525 affects versions of the Event Database extension for TYPO3 prior to 1.1.2.
4
What type of vulnerability is CVE-2008-2525?
CVE-2008-2525 is a cross-site scripting (XSS) vulnerability allowing remote script injection.
5
Who can exploit CVE-2008-2525?
Remote attackers can exploit CVE-2008-2525 by injecting malicious scripts through unspecified vectors.