Skip to main navigation Skip to main content Skip to page footer

Multiple Vulnerabilities found in TYPO3 CMS

10 December 2013 ยท TYPO3 Security Team
Dear TYPO3 users!

It has been discovered that TYPO3 CMS is vulnerable to Cross-Site Scripting, Information Disclosure, Mass Assignment, Open Redirection and Insecure Unserialize.

For more details on the issues please read the accordant advisory:

TYPO3 Security Bulletin TYPO3-CORE-SA-2013-004: TYPO3-CORE-SA-2013-004: Multiple Vulnerabilities in TYPO3 CMS
http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004/


In general the TYPO3 Security Team recommends to read the following pages:

The TYPO3 Security Guide:
http://docs.typo3.org/typo3cms/SecurityGuide/

See all TYPO3 security advisories:
http://typo3.org/teams/security/security-bulletins/

See all security related code changes in TYPO3 CMS:
https://review.typo3.org

Regards,

Helmut Hummel
Member of the TYPO3 Security Team