CVE-2011-4630: XSS
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the browselinks wizard.
Other sources
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the browselinks wizard.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is CVE-2011-4630?
CVE-2011-4630 is a vulnerability that allows remote attackers to inject arbitrary web script or HTML into TYPO3 versions before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4, leading to potential cross-site scripting (XSS) attacks.
How does CVE-2011-4630 affect TYPO3?
CVE-2011-4630 allows remote attackers to inject arbitrary web script or HTML through the browse_links wizard in TYPO3 versions before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4.
What is the severity of CVE-2011-4630?
CVE-2011-4630 has a severity rating of medium, with a CVSS score of 5.4.
Which software versions are affected by CVE-2011-4630?
TYPO3 versions before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 are affected by CVE-2011-4630.
How can I fix CVE-2011-4630 in TYPO3?
To fix CVE-2011-4630 in TYPO3, you should upgrade to version 4.3.12, 4.4.9, or 4.5.4 or later, as recommended in the TYPO3 security advisory.