CVE-2009-0257: XSS
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) content of indexed files to the (a) Indexed Search Engine (indexedsearch) system extension; (b) unspecified test scripts in the ADOdb system extension; and (c) unspecified vectors in the Workspace module.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0257?
CVE-2009-0257 is classified as having a high severity risk due to its potential to enable cross-site scripting attacks.
How do I fix CVE-2009-0257?
To fix CVE-2009-0257, upgrade TYPO3 to a version that is not affected by this vulnerability, specifically versions later than 4.2.3.
Which versions of TYPO3 are affected by CVE-2009-0257?
CVE-2009-0257 affects TYPO3 versions 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3.
What type of vulnerability is CVE-2009-0257?
CVE-2009-0257 is categorized as a cross-site scripting (XSS) vulnerability.
Can CVE-2009-0257 be exploited by remote attackers?
Yes, CVE-2009-0257 allows remote attackers to inject arbitrary web scripts or HTML.