CVE-2011-4632: XSS
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the tcemain flash message.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2011-4632?
CVE-2011-4632 is a cross-site scripting (XSS) vulnerability in TYPO3 before versions 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4.
How does CVE-2011-4632 affect TYPO3?
CVE-2011-4632 allows remote attackers to inject arbitrary web script or HTML via the tcemain flash message in TYPO3.
What is the severity of CVE-2011-4632?
The severity of CVE-2011-4632 is rated as medium with a CVSS score of 5.4.
How can I fix CVE-2011-4632?
To fix CVE-2011-4632, you should update TYPO3 to version 4.3.12, 4.4.9, or 4.5.4.
Where can I find more information about CVE-2011-4632?
You can find more information about CVE-2011-4632 at the following references: [1] https://security-tracker.debian.org/tracker/CVE-2011-4632 [2] https://typo3.org/security/advisory/typo3-core-sa-2011-001/#XSS