VYPR
Unrated severityNVD Advisory· Published Jan 22, 2009· Updated Apr 23, 2026

CVE-2009-0257

CVE-2009-0257

Description

Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) content of indexed files to the (a) Indexed Search Engine (indexed_search) system extension; (b) unspecified test scripts in the ADOdb system extension; and (c) unspecified vectors in the Workspace module.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple XSS vulnerabilities in TYPO3 4.0.0-4.2.3 allow remote attackers to inject arbitrary web script or HTML via indexed files, ADOdb test scripts, and the Workspace module.

Vulnerability

Multiple cross-site scripting (XSS) vulnerabilities exist in TYPO3 versions 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 [1]. The flaws are present in the Indexed Search Engine (indexed_search) system extension via the name and content of indexed files; in unspecified test scripts within the ADOdb system extension; and through unspecified vectors in the Workspace module. These issues allow injection of arbitrary web script or HTML [1].

Exploitation

An attacker can exploit these XSS vulnerabilities remotely without authentication. The attack requires the victim to interact with a malicious link or content that triggers the injection in the affected TYPO3 components. Specifically, the attacker must craft a request that includes injected script as the name or content of an indexed file, or via the ADOdb test scripts or Workspace module vectors. Successful exploitation occurs when the victim visits a page that renders the injected data [1].

Impact

Successful exploitation allows a remote attacker to execute arbitrary web script or HTML in the context of the affected site, potentially leading to session hijacking, defacement, or theft of sensitive data such as credentials. The impact is limited to the browser session and the trust level of the authenticated user, but can be used to perform actions on behalf of the victim [1].

Mitigation

TYPO3 released updated versions 4.0.10, 4.1.8, and 4.2.4 to fix these issues [1]. Users should upgrade to the latest available version or apply the security patches provided by the vendor. No workaround is documented in the available references. As of the publication date, the vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.

[1]: http://secunia.com/advisories/33679

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

25
  • TYPO3/Typo325 versions
    cpe:2.3:a:typo3:typo3:4.0:*:*:*:*:*:*:*+ 24 more
    • cpe:2.3:a:typo3:typo3:4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.1.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.1.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.1.7:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:typo3:typo3:4.2.3:*:*:*:*:*:*:*
    • (no CPE)range: 4.0.0-4.0.9, 4.1.0-4.1.7, 4.2.0-4.2.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.