TYPO3 Extensions Cross Site Scripting and SQL Injection Vulnerabilities
Description
Multiple vulnerabilities have been identified in various TYPO3 extensions, which could be exploited by attackers to manipulate or disclose certain data. These issues are caused by unspecified input validation errors when processing user-supplied data, which could allow information disclosure, cross site scripting and SQL injection attacks.
Vulnerable Products
Vulnerable Software: Vox populi (extension for TYPO3) version 0.3.0 and priorSB Universal Plugin (extension for TYPO3) version 2.0.1 and priorSimple File Browser (extension for TYPO3) version 1.0.2 and priorTU-Clausthal ODIN (extension for TYPO3) version 0.0.1TU-Clausthal ODIN (extension for TYPO3) version 0.1.0TU-Clausthal ODIN (extension for TYPO3) version 0.1.1TU-Clausthal ODIN (extension for TYPO3) version 0.2.0TU-Clausthal Staff (extension for TYPO3) version 0.3.0 and priorWEBERkommunal Facilities (extension for TYPO3) version 2.0.0 and prior