Description
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.ambionics.io/blog/typo3-news-module-sqli |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T16:04:11.913Z
Reserved: 2017-04-07T00:00:00.000Z
Link: CVE-2017-7581
No data.
Status : Modified
Published: 2017-04-07T19:59:00.200
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-7581
No data.
OpenCVE Enrichment
No data.
Weaknesses