PT-2023-10351 · Typo3 · Mback2K Mh Httpbl Extension
Nicole Cordes
·
Published
2023-06-01
·
Updated
2024-08-06
·
CVE-2016-15032
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
mback2k mh httpbl Extension versions 1.1.7 and earlier
Description
A problematic vulnerability has been found in the mback2k mh httpbl Extension on TYPO3, affecting the function
stopOutput of the file class.tx mhhttpbl.php. The manipulation of the argument $ SERVER['REMOTE ADDR'] leads to cross-site scripting. It is possible to initiate the attack remotely. This issue only affects products that are no longer supported by the maintainer.Recommendations
For versions 1.1.7 and earlier, upgrade to version 1.1.8 to address this issue. As a temporary workaround, consider restricting access to the
stopOutput function of the class.tx mhhttpbl.php file until the upgrade is applied. Additionally, be cautious when using the $ SERVER['REMOTE ADDR'] argument to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mback2K Mh Httpbl Extension