The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set and using a homepage with links that only contain anchors, allows remote attackers to change URLs to arbitrary domains for those links via unknown vectors.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-5301 The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set and using a homepage with links that only contain anchors, allows remote attackers to change URLs to arbitrary domains for those links via unknown vectors.
Github GHSA Github GHSA GHSA-v6xv-rmqc-wcc8 Typo3 Open Redirect In Frontend Rendering
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T13:47:41.065Z

Reserved: 2015-01-04T00:00:00

Link: CVE-2014-9508

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-01-04T21:59:05.887

Modified: 2025-04-12T10:46:40.837

Link: CVE-2014-9508

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses