HIGH
GHSA-9568-hcj9-rf7v
Webkit PDFs for TYPO3 has SQL Injection vulnerability
Quick fix
GHSA-9568-hcj9-rf7v — dmk/webkitpdf: upgrade to the fixed version with the command below.
composer require dmk/webkitpdf:^1.1.4Details
SQL injection vulnerability in the Webkit PDFs (webkitpdf) extension before 1.1.4 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2010-4961[ADVISORY]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61059[WEB]
- https://github.com/DMKEBUSINESSGMBH/webkitpdf[PACKAGE]
- https://web.archive.org/web/20101218181134/http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-015[WEB]
- https://web.archive.org/web/20111015170040/http://www.securityfocus.com/bid/42381[WEB]
- http://typo3.org/extensions/repository/view/webkitpdf/1.1.4[WEB]