CVE-2008-2718: XSS
Cross-site scripting (XSS) vulnerability in feadminlib.inc in TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, as used in extensions such as (1) directmailsubscription, (2) feuseradmin, and (3) kbmd5fepw, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2718?
The severity of CVE-2008-2718 is considered high due to its potential for cross-site scripting attacks.
How do I fix CVE-2008-2718?
To fix CVE-2008-2718, upgrade TYPO3 to version 4.0.9, 4.1.7, or 4.2.1 or later.
Which TYPO3 versions are affected by CVE-2008-2718?
CVE-2008-2718 affects TYPO3 versions 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1.
What types of extensions might be vulnerable with CVE-2008-2718?
Extensions such as direct_mail_subscription, feuser_admin, and kb_md5fepw may be vulnerable due to CVE-2008-2718.
Can CVE-2008-2718 lead to remote attacks?
Yes, CVE-2008-2718 can allow remote attackers to inject arbitrary web scripts or HTML into affected TYPO3 installations.