CVE-2009-0257
Description
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) content of indexed files to the (a) Indexed Search Engine (indexed_search) system extension; (b) unspecified test scripts in the ADOdb system extension; and (c) unspecified vectors in the Workspace module.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Multiple XSS vulnerabilities in TYPO3 4.0.0-4.2.3 allow remote attackers to inject arbitrary web script or HTML via indexed files, ADOdb test scripts, and the Workspace module.
Vulnerability
Multiple cross-site scripting (XSS) vulnerabilities exist in TYPO3 versions 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 [1]. The flaws are present in the Indexed Search Engine (indexed_search) system extension via the name and content of indexed files; in unspecified test scripts within the ADOdb system extension; and through unspecified vectors in the Workspace module. These issues allow injection of arbitrary web script or HTML [1].
Exploitation
An attacker can exploit these XSS vulnerabilities remotely without authentication. The attack requires the victim to interact with a malicious link or content that triggers the injection in the affected TYPO3 components. Specifically, the attacker must craft a request that includes injected script as the name or content of an indexed file, or via the ADOdb test scripts or Workspace module vectors. Successful exploitation occurs when the victim visits a page that renders the injected data [1].
Impact
Successful exploitation allows a remote attacker to execute arbitrary web script or HTML in the context of the affected site, potentially leading to session hijacking, defacement, or theft of sensitive data such as credentials. The impact is limited to the browser session and the trust level of the authenticated user, but can be used to perform actions on behalf of the victim [1].
Mitigation
TYPO3 released updated versions 4.0.10, 4.1.8, and 4.2.4 to fix these issues [1]. Users should upgrade to the latest available version or apply the security patches provided by the vendor. No workaround is documented in the available references. As of the publication date, the vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.
[1]: http://secunia.com/advisories/33679
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
25cpe:2.3:a:typo3:typo3:4.0:*:*:*:*:*:*:*+ 24 more
- cpe:2.3:a:typo3:typo3:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.1.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.1.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.3:*:*:*:*:*:*:*
- (no CPE)range: 4.0.0-4.0.9, 4.1.0-4.1.7, 4.2.0-4.2.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- secunia.com/advisories/33617nvdVendor Advisory
- typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/nvdVendor Advisory
- secunia.com/advisories/33679nvd
- www.debian.org/security/2009/dsa-1711nvd
- www.securityfocus.com/bid/33376nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/48133nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/48135nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/48136nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/48137nvd
News mentions
0No linked articles in our index yet.