First published: Thu May 22 2014(Updated: )
Failing to properly encode user input, several backend components are susceptible to XSS
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/typo3/cms | >=6.2.0<6.2.3 | |
composer/typo3/cms | >=6.2.0<6.2.3 | 6.2.3 |
composer/typo3/cms | >=6.1.0<=6.1.8 | 6.1.9 |
composer/typo3/cms | >=6.0.0<=6.0.13 | 6.0.14 |
composer/typo3/cms | >=4.7.0<=4.7.18 | 4.7.19 |
composer/typo3/cms | >=4.5.0<=4.5.33 | 4.5.34 |
TYPO3 | =4.5.0 | |
TYPO3 | =4.5.1 | |
TYPO3 | =4.5.2 | |
TYPO3 | =4.5.3 | |
TYPO3 | =4.5.4 | |
TYPO3 | =4.5.5 | |
TYPO3 | =4.5.6 | |
TYPO3 | =4.5.7 | |
TYPO3 | =4.5.8 | |
TYPO3 | =4.5.9 | |
TYPO3 | =4.5.10 | |
TYPO3 | =4.5.11 | |
TYPO3 | =4.5.12 | |
TYPO3 | =4.5.13 | |
TYPO3 | =4.5.14 | |
TYPO3 | =4.5.15 | |
TYPO3 | =4.5.16 | |
TYPO3 | =4.5.17 | |
TYPO3 | =4.5.18 | |
TYPO3 | =4.5.19 | |
TYPO3 | =4.5.20 | |
TYPO3 | =4.5.21 | |
TYPO3 | =4.5.22 | |
TYPO3 | =4.5.23 | |
TYPO3 | =4.5.24 | |
TYPO3 | =4.5.25 | |
TYPO3 | =4.5.26 | |
TYPO3 | =4.5.27 | |
TYPO3 | =4.5.28 | |
TYPO3 | =4.5.29 | |
TYPO3 | =4.5.30 | |
TYPO3 | =4.5.31 | |
TYPO3 | =4.5.32 | |
TYPO3 | =4.5.33 | |
TYPO3 | =6.0 | |
TYPO3 | =6.0.1 | |
TYPO3 | =6.0.2 | |
TYPO3 | =6.0.3 | |
TYPO3 | =6.0.4 | |
TYPO3 | =6.0.5 | |
TYPO3 | =6.0.6 | |
TYPO3 | =6.0.7 | |
TYPO3 | =6.0.8 | |
TYPO3 | =6.0.9 | |
TYPO3 | =6.0.10 | |
TYPO3 | =6.0.11 | |
TYPO3 | =6.0.12 | |
TYPO3 | =6.0.13 | |
TYPO3 | =6.2 | |
TYPO3 | =6.2.0-beta1 | |
TYPO3 | =6.2.0-beta2 | |
TYPO3 | =6.2.0-beta3 | |
TYPO3 | =6.2.1 | |
TYPO3 | =6.2.2 | |
TYPO3 | =6.1 | |
TYPO3 | =6.1.1 | |
TYPO3 | =6.1.2 | |
TYPO3 | =6.1.3 | |
TYPO3 | =6.1.4 | |
TYPO3 | =6.1.5 | |
TYPO3 | =6.1.6 | |
TYPO3 | =6.1.7 | |
TYPO3 | =6.1.8 | |
TYPO3 | =4.7.0 | |
TYPO3 | =4.7.1 | |
TYPO3 | =4.7.2 | |
TYPO3 | =4.7.3 | |
TYPO3 | =4.7.4 | |
TYPO3 | =4.7.5 | |
TYPO3 | =4.7.6 | |
TYPO3 | =4.7.7 | |
TYPO3 | =4.7.8 | |
TYPO3 | =4.7.9 | |
TYPO3 | =4.7.10 | |
TYPO3 | =4.7.11 | |
TYPO3 | =4.7.12 | |
TYPO3 | =4.7.13 | |
TYPO3 | =4.7.14 | |
TYPO3 | =4.7.15 | |
TYPO3 | =4.7.16 | |
TYPO3 | =4.7.17 | |
TYPO3 | =4.7.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3943 is classified as a medium severity vulnerability due to multiple cross-site scripting (XSS) issues.
To address CVE-2014-3943, upgrade TYPO3 to versions 4.5.34, 4.7.19, 6.0.14, 6.1.9, or 6.2.3 and ensure proper encoding of user input.
CVE-2014-3943 affects TYPO3 versions before 4.5.34, 4.7.19, 6.0.14, 6.1.9, and 6.2.3.
Risks include the potential for attackers to execute arbitrary scripts in the context of user sessions, leading to session hijacking or data theft.
As of now, there are no known active exploitation reports specific to CVE-2014-3943, but it is advisable to patch promptly.