Cross-site scripting (XSS) vulnerability in the Static Methods since 2007 (div2007) extension before 0.10.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the t3lib_div::quoteJSvalue function.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-4941 | Static Methods since 2007 (div2007) extension for TYPO3 vulnerable to Cross-site Scripting |
Github GHSA |
GHSA-4mm3-xgc2-656r | Static Methods since 2007 (div2007) extension for TYPO3 vulnerable to Cross-site Scripting |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T16:59:41.320Z
Reserved: 2013-08-09T00:00:00
Link: CVE-2013-5100
No data.
Status : Deferred
Published: 2013-08-09T22:55:03.790
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-5100
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA