TYPO3 Faceted Search Extension CVE-2013-5307 Unspecified Cross Site Scripting Vulnerability
BID:61609
Info
TYPO3 Faceted Search Extension CVE-2013-5307 Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 61609 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-5307 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2013 12:00AM |
| Updated: | Aug 21 2013 12:27PM |
| Credit: | Christian Bulter |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
TYPO3 Faceted Search Extension CVE-2013-5307 Unspecified Cross Site Scripting Vulnerability
The Faceted Search Extension for TYPO3 is prone to an unspecified cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Faceted Search 1.4.1 are vulnerable.
The Faceted Search Extension for TYPO3 is prone to an unspecified cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Faceted Search 1.4.1 are vulnerable.
Exploit / POC
TYPO3 Faceted Search Extension CVE-2013-5307 Unspecified Cross Site Scripting Vulnerability
To exploit this issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
To exploit this issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
TYPO3 Faceted Search Extension CVE-2013-5307 Unspecified Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
TYPO3 Faceted Search Extension CVE-2013-5307 Unspecified Cross Site Scripting Vulnerability
References:
References:
- TYPO3 Homepage (TYPO3)