First published: Thu Jul 22 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the Userdata Create/Edit (sg_userdata) extension before 0.91.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
stefan geith sg Userdata | <=0.90.300 | |
stefan geith sg Userdata | =0.90.100 | |
stefan geith sg Userdata | =0.90.101 | |
stefan geith sg Userdata | =0.90.109 | |
stefan geith sg Userdata | =0.90.111 | |
stefan geith sg Userdata | =0.90.202 | |
stefan geith sg Userdata | =0.90.210 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4953 is classified as having a critical severity due to its potential for cross-site scripting attacks.
To fix CVE-2009-4953, upgrade the sg_userdata extension to version 0.91.0 or later.
CVE-2009-4953 affects sg_userdata versions up to and including 0.90.300.
Yes, CVE-2009-4953 can potentially allow attackers to inject malicious scripts that lead to data loss.
CVE-2009-4953 impacts TYPO3 installations using affected versions of sg_userdata, exposing them to cross-site scripting vulnerabilities.