First published: Fri Jan 15 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the Vote rank for news (vote_for_tt_news) extension 1.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
francisco cifuentes Vote for tt news | <=1.0.1 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0335 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2010-0335, upgrade the Vote for tt news extension to version 1.0.2 or later.
CVE-2010-0335 affects the Vote for tt news extension versions 1.0.1 and earlier for TYPO3.
Using TYPO3 with an affected version of the Vote for tt news extension can expose your site to XSS attacks.
CVE-2010-0335 allows remote attackers to inject arbitrary web scripts or HTML into the application.