VDB
Sign up
HIGH

GHSA-g868-j3qm-4j28

georgringer/news has SQL Injection in extension "News system" (news)

Quick fix

GHSA-g868-j3qm-4j28 — georgringer/news: upgrade to the fixed version with the command below.

composer require georgringer/news:^12.3.2

Details

The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the TypoScript/Plugin setting disableOverrideDemand not to be enabled.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/georgringer/news
Introduced in: 12.0.0Fixed in: 12.3.2
Fixcomposer require georgringer/news:^12.3.2
Packagist/georgringer/news
Introduced in: 13.0.0Fixed in: 13.0.2
Fixcomposer require georgringer/news:^13.0.2
Packagist/georgringer/news
Introduced in: 14.0.0Fixed in: 14.0.3
Fixcomposer require georgringer/news:^14.0.3
Packagist/georgringer/news
Introduced in: 0Fixed in: 10.0.4
Fixcomposer require georgringer/news:^10.0.4
Packagist/georgringer/news
Introduced in: 11.0.0Fixed in: 11.4.4
Fixcomposer require georgringer/news:^11.4.4

References