Released on: 2013-06-03
Updated on: 2013-06-26
Affected Systems:
TYPO3 Maag Form Captcha <= 2.0.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 60298
CVE (CAN) ID: CVE-2013-4680
Typo3 is an open-source Content Management System (CMS) and Content Management Framework (CMF ).
TYPO3's Maag Form Captcha 2.0.0 and earlier versions have the open redirection vulnerability, which allows attackers to redirect users to any website and perform phishing attacks.
<* Source: Gerrit Vijlbrief
Link: http://xforce.iss.net/xforce/xfdb/84670
Http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2013-007/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
TYPO3
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://typo3.org/extensions/repository/