Skip to main navigation Skip to main content Skip to page footer

Multiple vulnerabilities in TYPO3 CMS

15 December 2015 ยท TYPO3 Security Team
Dear TYPO3 users!

It has been discovered that TYPO3 CMS is susceptible to Cross-Site Scripting and Cross-Site Flashing.

For details on the issues please read the accordant advisories:

TYPO3-CORE-SA-2015-010: Cross-Site Scripting in TYPO3 component Extension Manager
http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2015-010/

TYPO3-CORE-SA-2015-011: Multiple Cross-Site Scripting vulnerabilities in TYPO3 backend
http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2015-011/

TYPO3-CORE-SA-2015-012: Cross-Site Scripting vulnerability in typolinks
http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2015-012/

TYPO3-CORE-SA-2015-013: Multiple Cross-Site Scripting vulnerabilities in frontend
http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2015-013/

TYPO3-CORE-SA-2015-014: TYPO3 is susceptible to Cross-Site Flashing
http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2015-014/

TYPO3-CORE-SA-2015-015: Cross-Site Scripting in TYPO3 component Indexed Search
http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2015-015/



In general the TYPO3 Security Team recommends to read the following pages:

The TYPO3 Security Guide:
http://docs.typo3.org/typo3cms/SecurityGuide/

Make sure you are subscribed to the TYPO3 Announce List:
http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce

See all TYPO3 security advisories:
http://typo3.org/teams/security/security-bulletins/



Regards,

Helmut Hummel
Member of the TYPO3 Security Team

--
TYPO3 Security Team homepage: http://typo3.org/teams/security/

E-Mail: security@typo3.org