CVE-2009-0816

TYPO3 3.3.x-3.8.x, 4.0-4.0.11, 4.1-4.1.9, 4.2-4.2.5, 4.3alpha1 - Cross-Site Scripting in Backend User Interface

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in the backend user interface in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 allow remote attackers to inject arbitrary web script or HTML via unspecified fields.

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/02/10/6
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1720
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1021709

Scores

EPSS 0.0029
EPSS Percentile 52.0%

Details

CWE
CWE-79
Status published
Products (29)
typo3/cms 3.3.0Packagist
typo3/typo3 4.0
typo3/typo3 4.0.1
typo3/typo3 4.0.2
typo3/typo3 4.0.3
typo3/typo3 4.0.4
typo3/typo3 4.0.5
typo3/typo3 4.0.6
typo3/typo3 4.0.7
typo3/typo3 4.0.8
... and 19 more
Published Mar 05, 2009
Tracked Since Feb 18, 2026