First published: Tue Feb 14 2012(Updated: )
Cross-site scripting (XSS) vulnerability in lib/class.tx_jftcaforms_tceFunc.php in the Additional TCA Forms (jftcaforms) extension before 0.2.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jftcaforms | =0.0.1 | |
Jftcaforms | =0.0.2 | |
Jftcaforms | =0.1.0 | |
Jftcaforms | =0.1.1 | |
Jftcaforms | =0.2.0 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-5080 is classified as a cross-site scripting (XSS) vulnerability that can lead to potential data theft or site compromise.
To fix CVE-2011-5080, upgrade the Additional TCA Forms (jftcaforms) extension to version 0.2.1 or later.
CVE-2011-5080 affects users of the Additional TCA Forms (jftcaforms) extension versions 0.0.1 to 0.2.0 for TYPO3.
Attackers can exploit CVE-2011-5080 through cross-site scripting to inject malicious web scripts or HTML into web pages.
Vulnerable software versions under CVE-2011-5080 include jftcaforms versions 0.0.1, 0.0.2, 0.1.0, 0.1.1, and 0.2.0.