Skip to main navigation Skip to main content Skip to page footer

Multiple vulnerabilities in extension "Fe user statistic" (festat)

It has been discovered that the extension "Fe user statistic" (festat) is susceptible to Cross-Site Scripting, Insecure Unserialize and Information Disclosure.

Release Date: March 03, 2016

Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.

Affected Versions: version 0.3.2 and below

Vulnerability Type: Cross-Site Scripting, Insecure Unserialize and Information Disclosure

Severity: High

Suggested CVSS v2.0: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C (What's that?)

Problem Description: Failing to sanitize user input properly, festat is vulnerable to Cross-Site Scripting, Insecure Unserialize and Information Disclosure.

Solution: An updated version 0.3.3 is available from the TYPO3 Extension Manager and at https://typo3.org/extensions/repository/download/festat/0.3.3/t3x/. Users of the extension are advised to update the extension as soon as possible.

Credits: Credits go to Torben Hansen who discovered and reported this vulnerability.

 

General advice: Follow the recommendations that are given in the TYPO3 Security Guide. Please subscribe to the typo3-announce mailing list to receive future Security Bulletins via E-mail.