Cross-site scripting (XSS) vulnerability in the leave comment (feedback) feature in Typo 5.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) comment[author] (Name) and (2) comment[url] (Website) parameters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| typosphere | typo | * |
| typosphere | typo | 5.1.2 |
| typosphere | typo | 2.6.0 |
| typosphere | typo | 5.0.3 |
| typosphere | typo | 2.5.7 |
| typosphere | typo | 2.5.8 |
| typosphere | typo | 2.5.0 |
| typosphere | typo | 5.1.1 |
| typosphere | typo | 2.5.3 |
| typosphere | typo | 1.6.8 |
| typosphere | typo | 3.99.1 |
| typosphere | typo | 1.6 |
| typosphere | typo | 2.0.6 |
| typosphere | typo | 2.5.5 |
| typosphere | typo | 2.5.2 |
| typosphere | typo | 2.5.6 |
| typosphere | typo | 5.0.2 |
| typosphere | typo | 2.0.5 |
| typosphere | typo | 3.99.3 |
| typosphere | typo | 2.5.1 |
| typosphere | typo | 2.0.0 |
| typosphere | typo | 2.5.4 |
| typosphere | typo | 5.0.3.98 |
| typosphere | typo | 4.1.1 |
| typosphere | typo | 3.99.0 |
| typosphere | typo | 3.99.2 |
| typosphere | typo | 3.99.4 |
| typosphere | typo | 5.0.3.98.1 |
| typosphere | typo | 5.1 |
| typosphere | typo | 2.0.1 |
| typosphere | typo | 4.0.0 |
SQL injection vulnerability in the "Manage pages" feature (admin/pages) in Typo 5.1.3 and earlier allows remote authenticated users with "blog publisher" rights to execute arbitrary SQL commands via the search[published_at] parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| typosphere | typo | * |
| typosphere | typo | 5.1.2 |
| typosphere | typo | 2.6.0 |
| typosphere | typo | 5.0.3 |
| typosphere | typo | 2.5.7 |
| typosphere | typo | 2.5.8 |
| typosphere | typo | 2.5.0 |
| typosphere | typo | 5.1.1 |
| typosphere | typo | 2.5.3 |
| typosphere | typo | 1.6.8 |
| typosphere | typo | 3.99.1 |
| typosphere | typo | 1.6 |
| typosphere | typo | 2.0.6 |
| typosphere | typo | 2.5.5 |
| typosphere | typo | 2.5.2 |
| typosphere | typo | 2.5.6 |
| typosphere | typo | 5.0.2 |
| typosphere | typo | 2.0.5 |
| typosphere | typo | 3.99.3 |
| typosphere | typo | 2.5.1 |
| typosphere | typo | 2.0.0 |
| typosphere | typo | 2.5.4 |
| typosphere | typo | 5.0.3.98 |
| typosphere | typo | 4.1.1 |
| typosphere | typo | 3.99.0 |
| typosphere | typo | 3.99.2 |
| typosphere | typo | 3.99.4 |
| typosphere | typo | 5.0.3.98.1 |
| typosphere | typo | 5.1 |
| typosphere | typo | 2.0.1 |
| typosphere | typo | 4.0.0 |
Typo 5.1.3 and earlier uses a hard-coded salt for calculating password hashes, which makes it easier for attackers to guess passwords via a brute force attack.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-330,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| typosphere | typo | * |