CVE-2013-7074: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Content Editing Wizards in TYPO3 4.5.x before 4.5.32, 4.7.x before 4.7.17, 6.0.x before 6.0.12, 6.1.x before 6.1.7, and the development versions of 6.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 6.1.7 - Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 6.0.12 - Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 4.7.17 - Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 4.5.32 - Upgrade
Upgrade
TYPO3 Content Editing Wizardsto a version that resolves this vulnerability.Fixed in 4.5.32 - Upgrade
Upgrade
TYPO3 Content Editing Wizardsto a version that resolves this vulnerability.Fixed in 4.7.17 - Upgrade
Upgrade
TYPO3 Content Editing Wizardsto a version that resolves this vulnerability.Fixed in 6.0.12 - Upgrade
Upgrade
TYPO3 Content Editing Wizardsto a version that resolves this vulnerability.Fixed in 6.1.7 - Upgrade
Upgrade
TYPO3 Content Editing Wizardsto a version that resolves this vulnerability.Fixed in 6.2
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7074?
CVE-2013-7074 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2013-7074?
To fix CVE-2013-7074, upgrade TYPO3 to version 4.5.32, 4.7.17, 6.0.12, or 6.1.7, which contain patches for the vulnerability.
Which versions of TYPO3 are affected by CVE-2013-7074?
CVE-2013-7074 affects TYPO3 versions 4.5.x before 4.5.32, 4.7.x before 4.7.17, 6.0.x before 6.0.12, and 6.1.x before 6.1.7.
Who can exploit CVE-2013-7074?
CVE-2013-7074 can be exploited by remote authenticated users to inject arbitrary web scripts or HTML into the application.
What is a cross-site scripting vulnerability like CVE-2013-7074?
Cross-site scripting vulnerabilities, like CVE-2013-7074, allow attackers to execute malicious scripts in users' browsers, potentially leading to data theft or session hijacking.