Security Advisory

CVE-2014-9508

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-01-04 21:00:00
Last updated 2024-08-06 13:47:41
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set and using a homepage with links that only contain anchors, allows remote attackers to change URLs to arbitrary domains for those links via unknown vectors.