VulnerabilityModified
CVE-2009-3630
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to place arbitrary web sites in TYPO3 backend framesets via crafted parameters, related to a…
MEDIUM 5.5EPSS 1.98%
Does this matter?
Lower severity and a low EPSS score (1.98%). Track it; it rarely justifies an emergency change on its own.
Description
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to place arbitrary web sites in TYPO3 backend framesets via crafted parameters, related to a "frame hijacking" issue.
- CVSS 2.0
- 5.5 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
- EPSS
- 1.98% probability · 79th percentile
- CISA KEV
- Not listed
- Affected
- typo3/typo3
- Source
- secalert@redhat.com
References
- http://marc.info/?l=oss-security&m=125632856206736&w=2
- http://secunia.com/advisories/37122Vendor Advisory
- http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/Vendor Advisory
- http://www.securityfocus.com/bid/36801Patch
- http://www.vupen.com/english/advisories/2009/3009Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53920
- http://marc.info/?l=oss-security&m=125632856206736&w=2
- http://secunia.com/advisories/37122Vendor Advisory
- http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/Vendor Advisory
- http://www.securityfocus.com/bid/36801Patch
- http://www.vupen.com/english/advisories/2009/3009Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53920
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.