First published: Fri Oct 10 2014(Updated: )
Cross-site scripting (XSS) vulnerability in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extension 2.14.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via the tx_dmmjobcontrol_pi1[search][keyword] parameter to jobs/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kevin Renskers Dmmjobcontrol | <=2.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7200 is classified as a high severity cross-site scripting vulnerability.
To fix CVE-2014-7200, upgrade to a version of the JobControl extension that is higher than 2.14.0.
CVE-2014-7200 allows remote attackers to inject arbitrary scripts or HTML into web pages accessed by users.
Yes, CVE-2014-7200 remains a concern for any unsupported TYPO3 versions that utilize the vulnerable JobControl extension.
CVE-2014-7200 affects all versions of the JobControl extension up to and including version 2.14.0.