First published: Mon Jul 01 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the My quiz and poll (myquizpoll) extension before 2.0.6 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
kurt gusbeth myquizpoll | <=1.4.0 | |
kurt gusbeth myquizpoll | =0.1.1 | |
kurt gusbeth myquizpoll | =0.1.2 | |
kurt gusbeth myquizpoll | =0.1.3 | |
kurt gusbeth myquizpoll | =0.1.4 | |
kurt gusbeth myquizpoll | =0.1.5 | |
kurt gusbeth myquizpoll | =0.1.6 | |
kurt gusbeth myquizpoll | =0.1.7 | |
kurt gusbeth myquizpoll | =0.2.0 | |
kurt gusbeth myquizpoll | =0.2.1 | |
kurt gusbeth myquizpoll | =0.2.2 | |
kurt gusbeth myquizpoll | =0.3.0 | |
kurt gusbeth myquizpoll | =0.4.0 | |
kurt gusbeth myquizpoll | =1.0.0 | |
kurt gusbeth myquizpoll | =1.0.1 | |
kurt gusbeth myquizpoll | =1.1.0 | |
kurt gusbeth myquizpoll | =1.2.0 | |
kurt gusbeth myquizpoll | =1.3.0 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4746 has a moderate severity rating as it allows cross-site scripting (XSS) attacks.
To fix CVE-2013-4746, upgrade the My quiz and poll (myquizpoll) extension to version 2.0.6 or higher.
Versions of the My quiz and poll extension prior to 2.0.6, including 1.4.0 and earlier, are affected by CVE-2013-4746.
Yes, CVE-2013-4746 can potentially allow attackers to execute arbitrary scripts, which may lead to data leakage.
CVE-2013-4746 can be exploited by remote attackers who can inject malicious web scripts or HTML into the application.