First published: Fri Oct 20 2017(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified parameters to the extension manager, or unspecified parameters to unknown backend forms.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Typo3 Typo3 | =4.2.10 | |
Typo3 Typo3 | =4.1.11 | |
Typo3 Typo3 | =4.1.1 | |
Typo3 Typo3 | =4.2.4 | |
Typo3 Typo3 | =4.2.5 | |
Typo3 Typo3 | =4.2.11 | |
Typo3 Typo3 | =4.1.8 | |
Typo3 Typo3 | =4.1.6 | |
Typo3 Typo3 | =4.2.0 | |
Typo3 Typo3 | =4.2.8 | |
Typo3 Typo3 | =4.1.12 | |
Typo3 Typo3 | =4.2.3 | |
Typo3 Typo3 | =4.1.4 | |
Typo3 Typo3 | =4.2.1 | |
Typo3 Typo3 | =4.1.7 | |
Typo3 Typo3 | =4.3.2 | |
Typo3 Typo3 | =4.1.0 | |
Typo3 Typo3 | =4.1.13 | |
Typo3 Typo3 | =4.2.12 | |
Typo3 Typo3 | =4.2.6 | |
Typo3 Typo3 | =4.3.0 | |
Typo3 Typo3 | =4.1.9 | |
Typo3 Typo3 | =4.2.2 | |
Typo3 Typo3 | =4.3.3 | |
Typo3 Typo3 | =4.4.0 | |
Typo3 Typo3 | =4.1.3 | |
Typo3 Typo3 | =4.3.1 | |
Typo3 Typo3 | =4.2.7 | |
Typo3 Typo3 | =4.1.5 | |
Typo3 Typo3 | =4.1.10 | |
Typo3 Typo3 | =4.1.2 | |
Typo3 Typo3 | =4.2.9 | |
debian/typo3-src | ||
composer/typo3/cms-backend | >=4.4.0<4.4.1 | 4.4.1 |
composer/typo3/cms-backend | >=4.3.0<4.3.4 | 4.3.4 |
composer/typo3/cms-backend | >=4.2.0<4.2.13 | 4.2.13 |
composer/typo3/cms-backend | >=4.1.0<4.1.14 | 4.1.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.