TYPO3-EXT-SA-2014-002: Several vulnerabilities in third party extensions

Several vulnerabilities have been found in the following third-party TYPO3 extensions: alpha_sitemap, femanager ke_stats, outstats, px_phpids, smarty, wec_map

Release Date: February 12, 2014

Bulletin update: September 18, 2014 (added CVEs)

Please read first: This Collective Security Bulletin (CSB) is a listing of vulnerable extensions with neither significant download numbers, nor other special importance amongst the TYPO3 Community. The intention of CSBs is to reduce the workload of the TYPO3 Security Team and of the maintainers of extensions with vulnerabilities. Nevertheless, vulnerabilities in TYPO3 core or important extensions will still get the well-known single Security Bulletin each.

Please read the chapter in the Security Guide about the different types of Extension Security Bulletins.

All vulnerabilities affect third-party extensions. These extensions are not part of the TYPO3 default installation.

Extension: Alphabetic Sitemap (alpha_sitemap)

Affected Versions: 0.0.3 and all versions below

Vulnerability Type: Cross-Site Scripting

Severity: Medium

Suggested CVSS v2.0: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:P/RL:U/RC:C (What's that?)

CVE: CVE-2014-6291

Solution: Versions of this extension that are known to be vulnerable will no longer be available for download from the TYPO3 Extension Repository. The extension author failed in providing a security fix for the reported vulnerability in a decent amount of time. Please uninstall and delete the extension folder from your installation.

Credits: Credits go to Wouter Wolters who discovered and reported the issue.

Extension: femanager (femanager)

Affected Versions: 1.0.8 and all versions below

Vulnerability Type: Privilege Escalation

Severity: High

Suggested CVSS v2.0:  AV:N/AC:L/Au:S/C:P/I:C/A:N/E:F/RL:O/RC:C (What's that?)

CVE: CVE-2014-6292

Problem Description: Failing to properly check access rights, the extension is susceptible to privilege escalation, making it possible for a logged in frontend user to modify or delete other frontend user records.

Solution: An updated version 1.0.9 is available from the TYPO3 extension manager and at http://typo3.org/extensions/repository/download/femanager/1.0.9/t3x/. Users of the extension are advised to update the extension as soon as possible.

Extension: Statistics (ke_stats)

Affected Versions: 1.1.1 and all versions below

Vulnerability Type: SQL Injection

Severity: Critical

Suggested CVSS v2.0: AV:N/AC:L/Au:N/C:C/I:P/A:N/E:F/RL:O/RC:C (What's that?)

CVE: CVE-2014-6293

Solution: An updated version 1.1.2 is available from the TYPO3 extension manager and at http://typo3.org/extensions/repository/download/ke_stats/1.1.2/t3x/. Users of the extension are advised to update the extension as soon as possible.

Note: This vulnerability is known to be exploited in the wild.

Credits: Credits go to Extension Author Christian Bülter who discovered and reported the issue.

Extension: External links click statistics (outstats)

Affected Versions: 0.0.3 and all versions below

Vulnerability Type: Cross-Site Scripting

Severity: Medium

Suggested CVSS v2.0: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:P/RL:U/RC:C (What's that?)

CVE: CVE-2014-6294

Solution: Versions of this extension that are known to be vulnerable will no longer be available for download from the TYPO3 Extension Repository. The extension author failed in providing a security fix for the reported vulnerability in a decent amount of time. Please uninstall and delete the extension folder from your installation.

Credits: Credits go to TYPO3 Security Team Member Franz G. Jahn who discovered and reported the issue.

Extension: TYPO3 Security / Intrusion Detection System (px_phpids)

Affected Versions: 1.3.1 and all versions below

Vulnerability Type: Information Disclosure and Security Bypass

Severity: High

Suggested CVSS v2.0:  AV:N/AC:L/Au:N/C:P/I:P/A:P/E:P/RL:U/RC:C (What's that?)

Related CVEs: CVE-2011-5021, CVE-2011-3781

Solution: Versions of this extension that are known to be vulnerable will no longer be available for download from the TYPO3 Extension Repository. The extension author failed in providing a security fix for the reported vulnerability in a decent amount of time. Please uninstall and delete the extension folder from your installation.

Credits: Credits go to Bernd Wilke who discovered and reported the issue.

Extension: smarty (smarty)

Affected Versions: 1.13.3 and all versions below

Vulnerability Type: Arbitrary php include via template source file

Severity: Medium

Suggested CVSS v2.0:  AV:N/AC:H/Au:S/C:C/I:C/A:P/E:P/RL:O/RC:C (What's that?)

Problem Description: The extension smarty bundles the template engine smarty. Old versions of this library are known to be vulnerable to arbitrary php file include via template source file.

Solution: An updated version 1.13.4 is available from the TYPO3 extension manager and at http://typo3.org/extensions/repository/download/smarty/1.13.4/t3x/. Users of the extension are advised to update the extension as soon as possible.

Credits: Credits go to Extension Author Simon Tuck who discovered and reported the issue.

Extension: WEC Map (wec_map)

Affected Versions: 3.0.2 and all versions below

Vulnerability Type: SQL Injection and Cross-Site Scripting

Severity: Medium

Suggested CVSS v2.0: AV:N/AC:M/Au:N/C:C/I:P/A:N/E:P/RL:O/RC:C (What's that?)

CVE: CVE-2014-6295 (SQL Injection), CVE-2014-6296 (Cross-Site Scripting)

Solution: An updated version 3.0.3 is available from the TYPO3 extension manager and at http://typo3.org/extensions/repository/download/wec_map/3.0.3/t3x/. Users of the extension are advised to update the extension as soon as possible.

Credits: Credits go to Extension Author Jan Bartels who discovered and reported the issue.

General advice: Follow the recommendations that are given in the TYPO3 Security Guide. Please subscribe to the typo3-announce mailing list to receive future Security Bulletins via E-mail.