CRITICAL9.8
GHSA-598p-rv6p-g7qc
sr_freecap for Typo3 RCE Vulnerability
Quick fix
GHSA-598p-rv6p-g7qc — sjbr/sr-freecap: upgrade to the fixed version with the command below.
composer require sjbr/sr-freecap:^2.5.3Details
The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and below for TYPO3 fails to sanitize user input, which allows execution of arbitrary Extbase actions, resulting in Remote Code Execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/sjbr/sr-freecap
Introduced in:
2.5.0Fixed in: 2.5.3Fix
composer require sjbr/sr-freecap:^2.5.3