TYPO3-20070608-1: SQL injection in macina_banners / ric_rotation

It has been discovered that the extensions macina_banners and its descendant ric_rotation are exposed to an SQL injection issue because they fail to properly sanitize user-supplied input.

Component Type: Third party extensions. These extensions are not part of the TYPO3 default installation

Affected Versions: Affected is macina_banners (version 1.4.0 and below)
and its descendant ric_rotation (version 1.9.9 and below).
For clarification: ww_macinabanners is not affected.

Vulnerability Type: SQL injection

Severity: HIGH (exploitations have been reported, so it is supposed to be "in the wild")

Problem Description: These extensions are exposed to an SQL injection issue because it fails to properly sanitize user-supplied input.

Solution: Updated versions are available from the TYPO3 extension manager and at
typo3.org/extensions/repository/view/macina_banners/1.4.1/
and
typo3.org/extensions/repository/view/ric_rotation/1.9.10/
Users of these extensions are strongly advised to update the extension immediately.

General advice:
Follow the recommendations that are given in the TYPO3 SECURITY Guide.

Credits: Credits go to Jan Radecker who discovered this issue and to Wolfgang Becker and Clemens Riccabona who immediately fixed their extensions.