CVE-2010-3660: XSS
Published Nov 1, 2019
·Updated
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend.
Affected Software
9 affected componentsFixes available
composer/typo3/cms-backend>=4.4.0<4.4.1
4.4.1
composer/typo3/cms-backend>=4.3.0<4.3.4
4.3.4
composer/typo3/cms-backend>=4.2.0<4.2.13
4.2.13
composer/typo3/cms-backend<4.1.14
4.1.14
debian/typo3-src
Typo3 TYPO3>=4.4.0<4.4.1
Typo3 TYPO3>=4.3.0<4.3.4
Typo3 TYPO3<4.1.14
Typo3 TYPO3>=4.2.0<4.2.13
Event History
Nov 1, 2019
CVE Published
via MITRE·05:16 PM
Data Sourced
via MITRE·05:16 PM
Description
Apr 21, 2022
Advisory Published
via GitHub·01:57 AM
Frequently Asked Questions
1
What is the severity of CVE-2010-3660?
CVE-2010-3660 has been classified with a severity level that makes it a significant threat due to its potential to allow XSS attacks.
2
How do I fix CVE-2010-3660?
To resolve CVE-2010-3660, upgrade to TYPO3 version 4.4.1, 4.3.4, 4.2.13, or 4.1.14.
3
What types of attacks are possible due to CVE-2010-3660?
CVE-2010-3660 allows attackers to execute cross-site scripting (XSS) attacks within the TYPO3 backend.
4
Which TYPO3 versions are affected by CVE-2010-3660?
CVE-2010-3660 affects TYPO3 versions prior to 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1.
5
Are there any known exploits for CVE-2010-3660?
Yes, CVE-2010-3660 has been publicly reported and there are known exploits that utilize the XSS vulnerability.