CVE-2010-3672: XSS
Published Nov 5, 2019
·Updated
TYPO3 before 4.3.4 and 4.4.x before 4.4.1 allows XSS in the textarea view helper in an extbase extension.
Affected Software
5 affected componentsFixes available
composer/typo3/cms-fluid>=4.4.0<4.4.1
4.4.1
composer/typo3/cms-fluid<4.3.4
4.3.4
debian/typo3-src
Typo3 TYPO3>=4.4.0<4.4.1
Typo3 TYPO3<4.3.4
Event History
Nov 5, 2019
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
Description
Apr 21, 2022
Advisory Published
via GitHub·01:57 AM
Frequently Asked Questions
1
What is the severity of CVE-2010-3672?
CVE-2010-3672 has been rated as a medium severity vulnerability due to the potential for cross-site scripting (XSS).
2
How do I fix CVE-2010-3672?
To remediate CVE-2010-3672, update TYPO3 CMS to version 4.3.4 or later, or version 4.4.1 or later.
3
Which versions of TYPO3 are affected by CVE-2010-3672?
CVE-2010-3672 affects TYPO3 versions prior to 4.3.4 and versions in the 4.4.x series before 4.4.1.
4
What type of vulnerability is CVE-2010-3672?
CVE-2010-3672 is a cross-site scripting (XSS) vulnerability found in the textarea view helper of TYPO3.
5
What components does CVE-2010-3672 impact?
CVE-2010-3672 impacts the fluid component of TYPO3 CMS.