First published: Mon Nov 02 2009(Updated: )
Cross-site scripting (XSS) vulnerability in the Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/typo3/cms-install | >=4.3alpha1<4.3beta2 | 4.3beta2 |
composer/typo3/cms-install | >=4.2.0<4.2.10 | 4.2.10 |
composer/typo3/cms-install | >=4.1.0<4.1.13 | 4.1.13 |
composer/typo3/cms-install | <=4.0.13 | |
TYPO3 | <=4.0.12 | |
TYPO3 | =0.1.2 | |
TYPO3 | =1.0.14 | |
TYPO3 | =1.1 | |
TYPO3 | =1.1.1 | |
TYPO3 | =1.1.09 | |
TYPO3 | =1.1.10 | |
TYPO3 | =1.2.0 | |
TYPO3 | =1.3.0 | |
TYPO3 | =1.3.2 | |
TYPO3 | =3.0 | |
TYPO3 | =3.3.x | |
TYPO3 | =3.5 | |
TYPO3 | =3.5.x | |
TYPO3 | =3.6.x | |
TYPO3 | =3.7.0 | |
TYPO3 | =3.7.1 | |
TYPO3 | =3.7.x | |
TYPO3 | =3.8 | |
TYPO3 | =3.8.x | |
TYPO3 | =4.0 | |
TYPO3 | =4.0.1 | |
TYPO3 | =4.0.2 | |
TYPO3 | =4.0.3 | |
TYPO3 | =4.0.4 | |
TYPO3 | =4.0.5 | |
TYPO3 | =4.0.6 | |
TYPO3 | =4.0.7 | |
TYPO3 | =4.0.8 | |
TYPO3 | =4.0.9 | |
TYPO3 | =4.0.10 | |
TYPO3 | =4.0.11 | |
TYPO3 | =4.1.0 | |
TYPO3 | =4.1.0-beta1 | |
TYPO3 | =4.1.0-rc1 | |
TYPO3 | =4.1.1 | |
TYPO3 | =4.1.2 | |
TYPO3 | =4.1.3 | |
TYPO3 | =4.1.4 | |
TYPO3 | =4.1.5 | |
TYPO3 | =4.1.6 | |
TYPO3 | =4.1.7 | |
TYPO3 | =4.1.8 | |
TYPO3 | =4.1.9 | |
TYPO3 | =4.1.10 | |
TYPO3 | =4.1.11 | |
TYPO3 | =4.1.12 | |
TYPO3 | =4.2.0 | |
TYPO3 | =4.2.1 | |
TYPO3 | =4.2.2 | |
TYPO3 | =4.2.3 | |
TYPO3 | =4.2.4 | |
TYPO3 | =4.2.5 | |
TYPO3 | =4.2.6 | |
TYPO3 | =4.2.7 | |
TYPO3 | =4.2.8 | |
TYPO3 | =4.2.9 | |
TYPO3 | =4.3 | |
TYPO3 | =4.3-alpha1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3636 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2009-3636, upgrade TYPO3 to version 4.1.13, 4.2.10, or 4.3beta2 or newer.
CVE-2009-3636 allows remote attackers to inject arbitrary web scripts or HTML into affected TYPO3 installations.
Affected versions include TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2.
Currently, there are no known effective workarounds for CVE-2009-3636; the best mitigation is to upgrade to a patched version.