CVE-2010-3715: XSS
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the RemoveXSS function, and allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (2) the backend.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3715?
CVE-2010-3715 is classified as a high severity vulnerability allowing remote attackers to execute cross-site scripting (XSS) attacks.
How do I fix CVE-2010-3715?
To fix CVE-2010-3715, upgrade TYPO3 to versions 4.2.15, 4.3.7, or 4.4.4 or later.
What products are affected by CVE-2010-3715?
CVE-2010-3715 affects TYPO3 versions 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4.
Can CVE-2010-3715 be exploited by authenticated users?
Yes, CVE-2010-3715 allows remote authenticated users to inject arbitrary web scripts or HTML.
What kind of attacks can CVE-2010-3715 facilitate?
CVE-2010-3715 can facilitate cross-site scripting (XSS) attacks, which can compromise user data and site integrity.