VDB
Sign up
HIGH7.6

GHSA-5v5h-4w2g-gxxc

SQL Injection in t3/dce

Quick fix

GHSA-5v5h-4w2g-gxxc — t3/dce: upgrade to the fixed version with the command below.

composer require t3/dce:^2.6.2

Details

The dce (aka Dynamic Content Element) extension 2.2.0 through 2.6.x before 2.6.2, and 2.7.x before 2.7.1, for TYPO3 allows SQL Injection via a backend user account.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/t3/dce
Introduced in: 2.2.0Fixed in: 2.6.2
Fixcomposer require t3/dce:^2.6.2

References