CVE-2013-7078: XSS
Cross-site scripting (XSS) vulnerability in the errorAction method in the ActionController base class in the Extbase Framework in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6, when the Rewritten Property Mapper is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message. NOTE: this might be the same vulnerability as CVE-2013-7072.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 6.0.11 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 6.1.6 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 4.7.16 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 4.5.31
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7078?
CVE-2013-7078 is classified as a moderate severity vulnerability due to its potential for XSS attacks.
How do I fix CVE-2013-7078?
To fix CVE-2013-7078, upgrade TYPO3 to versions 4.5.31, 4.7.16, or 6.1.6 or later.
What does CVE-2013-7078 affect?
CVE-2013-7078 affects TYPO3 versions 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.1.6 when the Rewritten Property Mapper is enabled.
Who is vulnerable to CVE-2013-7078?
Remote attackers targeting installations of TYPO3 with affected versions may exploit CVE-2013-7078.
What type of vulnerability is CVE-2013-7078?
CVE-2013-7078 is a cross-site scripting (XSS) vulnerability.