First published: Sun Oct 09 2011(Updated: )
Cross-site scripting (XSS) vulnerability in the Branchenbuch (aka Yellow Pages or mh_branchenbuch) extension before 0.9.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Typo3 Branchenbuch Extension | <=0.9.0 | |
Typo3 Branchenbuch Extension | =0.7.95 | |
Typo3 Branchenbuch Extension | =0.8.0 | |
Typo3 Branchenbuch Extension | =0.8.1 | |
Typo3 Branchenbuch Extension | =0.8.2 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-4960 is considered medium due to its potential for cross-site scripting attacks.
To fix CVE-2010-4960, upgrade the Branchenbuch extension to version 0.9.1 or later.
CVE-2010-4960 affects versions of the Branchenbuch extension before 0.9.1, including 0.7.95 to 0.8.2.
CVE-2010-4960 is a cross-site scripting (XSS) vulnerability allowing attackers to inject scripts.
Yes, CVE-2010-4960 specifically affects TYPO3 installations using the vulnerable versions of the Branchenbuch extension.