All page names need to be in English.
en da  de  fr  it  ja  km  nl  ru  zh

TYPO3 4.5.32

From TYPO3Wiki
Jump to: navigation, search

<< Back to Administrators page


Release Notes for TYPO3 CMS 4.5.32

This document contains information about TYPO3 CMS 4.5.32 which was released on December 10th, 2013.


This release is a security release.


Due to security issues found in the TYPO3 Core, there was a combined release of TYPO3 4.5.32, 4.7.17, 6.0.12 and 6.1.7.
Find more details in the security bulletin:


MD5 checksums

f61c3e9a973d23e4a487c28d28ece5fa  blankpackage-4.5.32.tar.gz
e04ee38c259b5319743a7986d708c958  dummy-4.5.32.tar.gz
3ea6ddaf138087e993e59c60f9a29ff4  introductionpackage-4.5.32.tar.gz
a7dc7474dd60b210b97c60a3f07141fe  typo3_src-4.5.32.tar.gz


The usual upgrading procedure applies. No database updates are necessary.


Here is a list of what was fixed since 4.5.31:

  • [TASK] Set TYPO3 version to 4.5.33-dev
  • [RELEASE] Release of TYPO3 4.5.32
  • [SECURITY] XSS in header link of all content elements (#31206)
  • [SECURITY] XSS in colorpicker wizard (#42772)
  • [SECURITY] Prevent editor controlled hmac content (#45043)
  • Change-Id: I66b1ddc379577fc3ed67012384a15c38a6b76a03
  • [SECURITY] XSS vulnerability in extension manager (#20811)
  • [SECURITY] Information Disclosure in Wizards (#41714)
  • [SECURITY] Fix open redirection in openid extension (#54099)
  • [SECURITY] allows to set arbitrary fields (#48187)
  • [SECURITY] XSS in be_layout wizard (#36768)
  • [SECURITY] Remove possible XSS from ActionController Error output (#54074)
  • [SECURITY] Unsafe unserialize of GET parameter in Add-Wizard (#54073)
  • [BUGFIX] Fix failing test (#54282)
  • [BUGFIX] Fix failing test (#54280)
  • [BUGFIX] ClientUtility does not detect Internet Explorer 11 (#54124)
  • Revert "[BUGFIX] Object passed to date() versions. (#54120)
  • [BUGFIX] ext:adodb Restrict connection wizard to admins (#42651)
  • [BUGFIX] Distinguish unassigend columns and colPos 0 (#25157)
  • [TASK] Set TYPO3 version to 4.5.32-dev

Past Release Notes

If you have skipped one or more versions while upgrading to this version, please make sure to read the ReleaseNotes of these versions as well.