Multiple cross-site scripting (XSS) vulnerabilities in the Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1926-1 New TYPO3 packages fix several vulnerabilities
EUVD EUVD EUVD-2022-3923 Multiple cross-site scripting (XSS) vulnerabilities in the Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Github GHSA Github GHSA GHSA-g857-p997-wx7w TYPO3 Backend vulnerable to Cross-site Scripting
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T06:38:28.461Z

Reserved: 2009-10-09T00:00:00

Link: CVE-2009-3629

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2009-11-02T15:30:00.627

Modified: 2025-04-09T00:30:58.490

Link: CVE-2009-3629

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.