CVE-2013-7078

TYPO3 4.5.0-4.5.31, 4.7.0-4.7.16, 6.0.0-6.0.11, 6.1.0-6.1.6 - Cross-Site Scripting via Error Message

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the errorAction method in the ActionController base class in the Extbase Framework in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6, when the Rewritten Property Mapper is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message. NOTE: this might be the same vulnerability as CVE-2013-7072.

References (6)

Core 6
Core References
Mailing List mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2013/q4/487
Mailing List mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2013/q4/473
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/64239
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/89629
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/100885

Scores

EPSS 0.0049
EPSS Percentile 65.6%

Details

CWE
CWE-79
Status published
Products (50)
typo3/cms-core 4.5.0 - 4.5.31Packagist
typo3/typo3 6.0
typo3/typo3 6.0.1
typo3/typo3 6.0.2
typo3/typo3 6.0.3
typo3/typo3 6.0.4
typo3/typo3 6.0.5
typo3/typo3 6.0.6
typo3/typo3 6.0.7
typo3/typo3 6.0.8
... and 40 more
Published Jan 19, 2014
Tracked Since Feb 18, 2026