CVE-2012-1076: XSS
Cross-site scripting (XSS) vulnerability in the Documents download (rtgfiles) extension before 1.5.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1076?
CVE-2012-1076 is classified as a medium severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2012-1076?
To fix CVE-2012-1076, upgrade the Documents download (rtg_files) extension to version 1.5.2 or later.
What impact does CVE-2012-1076 have on TYPO3?
CVE-2012-1076 allows remote attackers to inject arbitrary web scripts or HTML, potentially compromising user data and session integrity.
Which versions of the rtg_files extension are affected by CVE-2012-1076?
CVE-2012-1076 affects versions prior to 1.5.2 of the rtg_files extension, including versions 1.4.7, 1.4.9, 1.4.10, and 1.5.0.
Is TYPO3 itself vulnerable due to CVE-2012-1076?
No, TYPO3 itself is not vulnerable as the issue is specific to the Documents download (rtg_files) extension.