Release date:
Updated on: 2014-06-04
Affected Systems:
TYPO3 TYPO3 6.x
TYPO3 TYPO3 4.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-3943
Typo3 is an open-source Content Management System (CMS) and Content Management Framework (CMF ).
In versions earlier than TYPO3 4.5.34, 4.7.19, 6.0.14, 6.1.9, and 6.2.3, some backend components have Multiple XSS vulnerabilities, this allows the authenticated remote editor to inject arbitrary Web scripts or HTML through some parameters.
<* Source: Helmut Hummel
Link: http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
TYPO3
-----
TYPO3 has released a Security Bulletin (typo3-core-sa-2014-001) and corresponding patches for this:
Typo3-core-sa-2014-001: TYPO3-CORE-SA-2014-001: Multiple Vulnerabilities in TYPO3 CMS
Link: http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001/
For more information about Typo3, click here.
Typo3: click here
This article permanently updates the link address: