HIGH
GHSA-g868-j3qm-4j28
georgringer/news has SQL Injection in extension "News system" (news)
Quick fix
GHSA-g868-j3qm-4j28 — georgringer/news: upgrade to the fixed version with the command below.
composer require georgringer/news:^12.3.2Details
The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the TypoScript/Plugin setting disableOverrideDemand not to be enabled.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/georgringer/news
Introduced in:
12.0.0Fixed in: 12.3.2Fix
composer require georgringer/news:^12.3.2Packagist/georgringer/news
Introduced in:
13.0.0Fixed in: 13.0.2Fix
composer require georgringer/news:^13.0.2Packagist/georgringer/news
Introduced in:
14.0.0Fixed in: 14.0.3Fix
composer require georgringer/news:^14.0.3Packagist/georgringer/news
Introduced in:
0Fixed in: 10.0.4Fix
composer require georgringer/news:^10.0.4Packagist/georgringer/news
Introduced in:
11.0.0Fixed in: 11.4.4Fix
composer require georgringer/news:^11.4.4