-
TYPO3-CORE-SA-2019-014: Information Disclosure in Backend User Interface
Categories: DevelopmentAdvisory type: TYPO3 CMSRead moreIt has been discovered that TYPO3 CMS is susceptible to information disclosure.
-
TYPO3-PSA-2019-008: By-passing protection of Phar Stream Wrapper Interceptor
Categories: DevelopmentAdvisory type: Public Service AnnouncementsRead moreIt has been discovered that the protection against insecure deserialization can be by-passed in Phar Stream Wrapper component.
-
TYPO3-PSA-2019-007: By-passing protection of Phar Stream Wrapper Interceptor
Categories: DevelopmentAdvisory type: Public Service AnnouncementsRead moreIt has been discovered that the protection against insecure deserialization can be by-passed in Phar Stream Wrapper component.
-
TYPO3-EXT-SA-2019-013: SQL Injection in extension "comsolit Suggest" (comsolit_suggest)
Categories: DevelopmentAdvisory type: TYPO3 ExtensionsRead moreIt has been discovered that the extension "comsolit Suggest" (comsolit_suggest) is susceptible to SQL Injection.
-
TYPO3-EXT-SA-2019-012: Arbitrary file Upload in extension "Yet Another Gallery" (yag)
Categories: DevelopmentAdvisory type: TYPO3 ExtensionsRead moreIt has been discovered that the extension "Yet Another Gallery" (yag) is susceptible to Arbitrary File Upload.
-
TYPO3-EXT-SA-2019-011: SQL Injection in extension "Event Calender" (pits_wd_calender)
Categories: DevelopmentAdvisory type: TYPO3 ExtensionsRead moreIt has been discovered that the extension "Event Calender" (pits_wd_calender) is susceptible to SQL Injection.
-
TYPO3-EXT-SA-2019-010: Cross Site Scripting in extension "Instagram" (ws_instagram)
Categories: DevelopmentAdvisory type: TYPO3 ExtensionsRead moreIt has been discovered that the extension "Instagram" (ws_instagram) is susceptible to Cross Site Scripting.
-
TYPO3-EXT-SA-2019-009: Cross Site Scripting in extension "gkh RSS Import" (gkh_rss_import)
Categories: DevelopmentAdvisory type: TYPO3 ExtensionsRead moreIt has been discovered that the extension "gkh RSS Import" (gkh_rss_import) is susceptible to Cross Site Scripting.
-
TYPO3-EXT-SA-2019-008: Multiple vulnerabilities in extension "phpMyAdmin" (phpmyadmin)
Categories: DevelopmentAdvisory type: TYPO3 ExtensionsRead moreIt has been discovered that the extension "phpMyAdmin" (phpmyadmin) is susceptible to Arbitrary file read and SQL injection.
-
TYPO3-EXT-SA-2019-007: Remote Code Execution in extension "ImageOptimizer" (imageoptimizer)
Categories: DevelopmentAdvisory type: TYPO3 ExtensionsRead moreIt has been discovered that the extension "ImageOptimizer" (imageoptimizer) is susceptible to Remote Code Execution.