CVE-2009-4948: XSS
Published Jul 22, 2010
·Updated
Cross-site scripting (XSS) vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
6 affected components
Joachim Ruhs Locator<=1.2.6
Joachim Ruhs Locator=1.0.6
Joachim Ruhs Locator=1.0.7
Joachim Ruhs Locator=1.1.0
Joachim Ruhs Locator=1.1.8
Typo3 TYPO3
Remediation
Patch Available
Event History
Jul 22, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
06:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4948?
CVE-2009-4948 is classified as a high severity vulnerability due to its potential for enabling cross-site scripting attacks.
2
How do I fix CVE-2009-4948?
To fix CVE-2009-4948, update the Store Locator extension to version 1.2.8 or later.
3
Which versions of the Store Locator extension are affected by CVE-2009-4948?
CVE-2009-4948 affects Store Locator versions prior to 1.2.8, including versions 1.0.6, 1.0.7, 1.1.0, 1.1.8, and all versions up to 1.2.6.
4
Is TYPO3 itself vulnerable due to CVE-2009-4948?
No, TYPO3 itself is not vulnerable; the issue is specifically related to the Store Locator extension.
5
What types of attacks can be executed due to CVE-2009-4948?
CVE-2009-4948 allows attackers to inject arbitrary web scripts or HTML into the affected application.