Description
|
|
Multiple vulnerabilities have been identified in TYPO3, which could be exploited by attackers to bypass security restrictions, gain knowledge of sensitive information or compromise a vulnerable system. These issues are caused by input validation and design errors in the Backend, Frontend Editing, Frontend Login Box (felogin) and Install Tool components, and within the API function "t3lib_div::quoteJSvalue" when processing user-supplied URL parameters or data, which could allow cross site scripting and SQL injection attacks, information disclosure, frame and session hijacking, and shell command injection.
|