CVE-2013-5305: XSS
Published Aug 16, 2013
·Updated
Cross-site scripting (XSS) vulnerability in the Store Locator (locator) extension before 3.1.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
9 affected components
Joachim Ruhs Locator<=2.9.1
Joachim Ruhs Locator=1.0.6
Joachim Ruhs Locator=1.0.7
Joachim Ruhs Locator=1.1.0
Joachim Ruhs Locator=1.1.8
Joachim Ruhs Locator=1.2.6
Joachim Ruhs Locator=1.2.8
Joachim Ruhs Locator=2.9.0
Typo3 TYPO3
Remediation
Patch Available
Event History
Aug 16, 2013
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5305?
CVE-2013-5305 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
2
How do I fix CVE-2013-5305?
To fix CVE-2013-5305, update the Store Locator extension to version 3.1.5 or later.
3
What systems are affected by CVE-2013-5305?
CVE-2013-5305 affects versions of the Store Locator extension prior to 3.1.5 for TYPO3.
4
What type of vulnerability is CVE-2013-5305?
CVE-2013-5305 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
5
Can remote attackers exploit CVE-2013-5305?
Yes, remote attackers can exploit CVE-2013-5305 to inject arbitrary web scripts or HTML through vulnerable vectors.