CVE-2013-7082: XSS
Cross-site scripting (XSS) vulnerability in the errorAction method in the ActionController base class in TYPO3 Flow (formerly FLOW3) 1.1.x before 1.1.1 and 2.0.x before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/typo3/flowto a version that resolves this vulnerability.Fixed in 2.0.1 - Upgrade
Upgrade
composer/typo3/flowto a version that resolves this vulnerability.Fixed in 1.1.1 - Upgrade
Upgrade
composer/neos/flowto a version that resolves this vulnerability.Fixed in 2.0.1 - Upgrade
Upgrade
composer/neos/flowto a version that resolves this vulnerability.Fixed in 1.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7082?
CVE-2013-7082 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2013-7082?
To fix CVE-2013-7082, upgrade TYPO3 Flow to version 1.1.1 or 2.0.1 or later.
Which software versions are affected by CVE-2013-7082?
Affected versions of TYPO3 Flow are 1.1.0 to 1.1.1 and 2.0.0 to 2.0.1.
What type of vulnerability is CVE-2013-7082?
CVE-2013-7082 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web script or HTML.
Can remote attackers exploit CVE-2013-7082?
Yes, remote attackers can exploit CVE-2013-7082 to inject malicious web scripts into error messages.