CVE-2013-7077: XSS
Cross-site scripting (XSS) vulnerability in the Backend User Administration Module in TYPO3 6.0.x before 6.0.12 and 6.1.x before 6.1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 6.1.7 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 6.0.12
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7077?
CVE-2013-7077 has a medium severity rating due to its potential impact on user data and security.
How do I fix CVE-2013-7077?
To fix CVE-2013-7077, upgrade TYPO3 to version 6.0.12 or later for 6.0.x and to version 6.1.7 or later for 6.1.x.
What are the affected versions of TYPO3 for CVE-2013-7077?
CVE-2013-7077 affects TYPO3 versions before 6.0.12 and 6.1.7 across multiple 6.0.x and 6.1.x releases.
Can CVE-2013-7077 allow remote attacks?
Yes, CVE-2013-7077 allows remote attackers to inject arbitrary web scripts or HTML, leading to cross-site scripting (XSS) attacks.
What module is vulnerable in CVE-2013-7077?
The Backend User Administration Module in TYPO3 is the component that contains the vulnerability described in CVE-2013-7077.