CVE-2012-1606: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Backend component in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1606?
CVE-2012-1606 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2012-1606?
To fix CVE-2012-1606, upgrade TYPO3 to versions 4.4.14, 4.5.14, or 4.6.7 or later.
Who is affected by CVE-2012-1606?
CVE-2012-1606 affects TYPO3 versions from 4.4.0 to 4.6.6, as well as versions 4.7 and 6.0.
What types of attacks can CVE-2012-1606 enable?
CVE-2012-1606 can enable remote authenticated users to perform cross-site scripting (XSS) attacks.
Is there a risk of data theft with CVE-2012-1606?
Yes, the risk of data theft exists as attackers can inject arbitrary web scripts or HTML through CVE-2012-1606.