CVE-2011-4631: XSS
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the system extension recycler.
Affected Software
Event History
Frequently Asked Questions
What is Cross-site Scripting (XSS)?
Cross-site Scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
What version of TYPO3 is affected by CVE-2011-4631?
TYPO3 versions before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 are affected by CVE-2011-463.
How does CVE-2011-4631 affect TYPO3?
CVE-2011-4631 allows remote attackers to inject arbitrary web script or HTML into web pages through the system extension recycler in TYPO3.
How severe is the vulnerability in CVE-2011-4631?
The severity of CVE-2011-4631 is medium, with a CVSS score of 5.4.
How can I mitigate the Cross-site Scripting (XSS) vulnerability in TYPO3?
To mitigate the Cross-site Scripting (XSS) vulnerability in TYPO3, you should update to TYPO3 versions 4.3.12, 4.4.9, or 4.5.4 and apply the necessary security patches.