|
TYPO3 WEC Discussion Forum Security Bypass and Multiple Cross Site Scripting Vulnerabilities
WEC Discussion Forum is prone to a security-bypass issue and multiple cross-site scripting issues because it fails to sufficiently sanitize user-supplied data. An attacker may exploit the security-bypass vulnerability to upload arbitrary files and execute script code in the context of the webserver process. The attacker may also leverage the cross-site scripting issues to execute script code in an unsuspecting user's browser or to steal cookie-based authentication credentials; other attacks are also possible. These issues affect versions prior to WEC Discussion Forum 1.6.3. |
|
|
Privacy Statement |