First published: Thu Jul 22 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Locator | <=1.2.6 | |
Locator | =1.0.6 | |
Locator | =1.0.7 | |
Locator | =1.1.0 | |
Locator | =1.1.8 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4948 is classified as a high severity vulnerability due to its potential for enabling cross-site scripting attacks.
To fix CVE-2009-4948, update the Store Locator extension to version 1.2.8 or later.
CVE-2009-4948 affects Store Locator versions prior to 1.2.8, including versions 1.0.6, 1.0.7, 1.1.0, 1.1.8, and all versions up to 1.2.6.
No, TYPO3 itself is not vulnerable; the issue is specifically related to the Store Locator extension.
CVE-2009-4948 allows attackers to inject arbitrary web scripts or HTML into the affected application.