First published: Tue Feb 14 2012(Updated: )
Open redirect vulnerability in the Modern FAQ (irfaq) extension 1.1.2 and other versions before 1.1.4 for TYPO3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL, probably in the "return url parameter."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
netcreators irfaq | <=1.1.2 | |
netcreators irfaq | =1.0.1 | |
netcreators irfaq | =1.0.2 | |
netcreators irfaq | =1.1.0 | |
netcreators irfaq | =1.1.1 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-5079 has a medium severity rating due to its potential for exploitation via phishing attacks.
To fix CVE-2011-5079, upgrade the Modern FAQ (irfaq) extension to version 1.1.4 or later.
CVE-2011-5079 affects users of the Modern FAQ (irfaq) extension versions 1.1.2 and earlier.
CVE-2011-5079 enables remote attackers to conduct phishing attacks through open redirect vulnerabilities.
No, TYPO3 itself is not directly vulnerable according to CVE-2011-5079, only the irfaq extension is affected.