CVE-2008-5644: XSS
Cross-site scripting (XSS) vulnerability in the file backend module in TYPO3 4.2.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/typo3/cms-backendto a version that resolves this vulnerability.Fixed in 4.2.3
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5644?
CVE-2008-5644 has been classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2008-5644?
To remediate CVE-2008-5644, upgrade TYPO3 from version 4.2.2 to 4.2.3 or later.
What versions of TYPO3 are affected by CVE-2008-5644?
CVE-2008-5644 affects TYPO3 version 4.2.2.
Can CVE-2008-5644 be exploited remotely?
Yes, CVE-2008-5644 can be exploited by remote attackers through cross-site scripting.
What is the nature of the vulnerability in CVE-2008-5644?
CVE-2008-5644 is a cross-site scripting (XSS) vulnerability, allowing arbitrary web script or HTML injection.