CVE-2012-3528: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the backend in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3528?
CVE-2012-3528 is classified as a medium-severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2012-3528?
To fix CVE-2012-3528, you should upgrade TYPO3 to version 4.5.19, 4.6.12, or 4.7.4 or later.
Which versions of TYPO3 are affected by CVE-2012-3528?
CVE-2012-3528 affects TYPO3 versions 4.5.x before 4.5.19, 4.6.x before 4.6.12, and 4.7.x before 4.7.4.
Can CVE-2012-3528 be exploited by unauthenticated users?
No, CVE-2012-3528 requires remote authenticated backend users to exploit the vulnerabilities.
What types of attacks can occur due to CVE-2012-3528?
CVE-2012-3528 can enable attackers to perform cross-site scripting (XSS) attacks, allowing them to inject arbitrary web scripts or HTML.