CVE-2012-1608: Input Validation
The t3libdiv::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web script or HTML via non printable characters.
Other sources
The t3libdiv::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web script or HTML via non printable characters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1608?
CVE-2012-1608 is considered a high severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2012-1608?
To fix CVE-2012-1608, users should upgrade to TYPO3 version 4.6.7 or later, 4.5.14 or later, or 4.4.14 or later.
What versions of TYPO3 are affected by CVE-2012-1608?
CVE-2012-1608 affects TYPO3 versions 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, as well as version 4.7 and 6.0.
Can CVE-2012-1608 be exploited remotely?
Yes, the vulnerability CVE-2012-1608 can be exploited remotely to inject arbitrary web script or HTML.
What is the impact of an attack using CVE-2012-1608?
An attacker exploiting CVE-2012-1608 can bypass XSS protection mechanisms, leading to potential data theft, session hijacking, or other malicious actions.