VDB
Sign up
HIGH

GHSA-f3v6-g4mv-pjhq

WEC Map (wec_map) extension for TYPO3 allows SQL Injection

Quick fix

GHSA-f3v6-g4mv-pjhq — web-tp3/wec_map: upgrade to the fixed version with the command below.

composer require web-tp3/wec_map:^3.0.3

Details

SQL injection vulnerability in the WEC Map (wec_map) extension before 3.0.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/web-tp3/wec_map
Introduced in: 0Fixed in: 3.0.3
Fixcomposer require web-tp3/wec_map:^3.0.3
Packagist/jbartels/wec-map
Introduced in: 0Fixed in: 3.0.3
Fixcomposer require jbartels/wec-map:^3.0.3

References