HIGH
GHSA-rg6g-v4xm-g49q
News system (news) extension for TYPO3 vulnerable to SQL Injection
Quick fix
GHSA-rg6g-v4xm-g49q — georgringer/news: upgrade to the fixed version with the command below.
composer require georgringer/news:^1.3.3Details
SQL injection vulnerability in the News system (news) extension before 1.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/georgringer/news
Introduced in:
0Fixed in: 1.3.3Fix
composer require georgringer/news:^1.3.3References
- https://nvd.nist.gov/vuln/detail/CVE-2013-4748[ADVISORY]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81192[WEB]
- https://github.com/georgringer/news[PACKAGE]
- https://web.archive.org/web/20130214093535/http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2013-001[WEB]
- http://typo3.org/extensions/repository/view/news[WEB]