Cross-site scripting (XSS) vulnerability in the t3lib_div::quoteJSvalue API function in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the sanitizing algorithm.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/ | patch vendor advisory |
http://secunia.com/advisories/37122 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/53925 | vdb entry |
http://marc.info/?l=oss-security&m=125633199111438&w=2 | mailing list |
http://marc.info/?l=oss-security&m=125632856206736&w=2 | mailing list |
http://www.vupen.com/english/advisories/2009/3009 | vdb entry patch vendor advisory |
http://www.securityfocus.com/bid/36801 | vdb entry patch |