HIGH7.6
GHSA-5v5h-4w2g-gxxc
SQL Injection in t3/dce
Quick fix
GHSA-5v5h-4w2g-gxxc — t3/dce: upgrade to the fixed version with the command below.
composer require t3/dce:^2.6.2Details
The dce (aka Dynamic Content Element) extension 2.2.0 through 2.6.x before 2.6.2, and 2.7.x before 2.7.1, for TYPO3 allows SQL Injection via a backend user account.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-31777[ADVISORY]
- https://bitbucket.org/ArminVieweg/dce/commits/998a2392f69f2153797c5ace6e8914ca309e70c7[WEB]
- https://excellium-services.com/cert-xlm-advisory[WEB]
- https://packagist.org/packages/t3/dce[WEB]
- https://typo3.org/security/advisory/typo3-ext-sa-2021-005[WEB]
- http://packetstormsecurity.com/files/162429/TYPO3-6.2.1-SQL-Injection.html[WEB]