CVE-2014-9508 Information
Feb 14, 2021
cve
Description
The frontend rendering component in TYPO3 4.5.x before 4.5.39 4.6.x through 6.2.x before 6.2.9 and 7.x before 7.0.2 when config.prefixLocalAnchors is set and using a homepage with links that only contain anchors allows remote attackers to change URLs to arbitrary domains for those links via unknown vectors.
Reference
http://lists.opensuse.org/opensuse-updates/2016-08/msg00106.html http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-003/
Share on: