-
TYPO3-CORE-SA-2019-008: Arbitrary Code Execution via File List Module
Categories: DevelopmentAdvisory type: TYPO3 CMSRead moreIt has been discovered, that TYPO3 CMS is vulnerable to arbitrary code execution.
-
TYPO3-CORE-SA-2019-007: Cross-Site Scripting in Form Framework
Categories: DevelopmentAdvisory type: TYPO3 CMSRead moreIt has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
-
TYPO3-CORE-SA-2019-006: Cross-Site Scripting in Bootstrap CSS toolkit
Categories: DevelopmentAdvisory type: TYPO3 CMSRead moreIt has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
-
TYPO3-CORE-SA-2019-005: Cross-Site Scripting in Fluid ViewHelpers
Categories: DevelopmentAdvisory type: TYPO3 CMSRead moreIt has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
-
TYPO3-CORE-SA-2019-004: Cross-Site Scripting in Language Pack Handling
Categories: DevelopmentAdvisory type: TYPO3 CMSRead moreIt has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
-
TYPO3-EXT-SA-2019-004: Object Injection in extension "mkmailer" (mkmailer)
Categories: DevelopmentAdvisory type: TYPO3 ExtensionsRead moreIt has been discovered that the extension "mkmailer" (mkmailer) is susceptible to Object Injection.
-
TYPO3-CORE-SA-2019-003: Broken Access Control in Localization Handling
Categories: DevelopmentAdvisory type: TYPO3 CMSRead moreIt has been discovered, that TYPO3 CMS is susceptible to broken access control.
-
TYPO3-EXT-SA-2019-003: Multiple vulnerabilities in extension "femanager" (femanager)
Categories: DevelopmentAdvisory type: TYPO3 ExtensionsRead moreIt has been discovered that the extension "femanager" (femanager) is susceptible to Validation Bypass and Information Disclosure
-
TYPO3-CORE-SA-2019-002: Security Misconfiguration for Backend User Accounts
Categories: DevelopmentAdvisory type: TYPO3 CMSRead moreIt has been discovered, that TYPO3 CMS is susceptible to security misconfiguration.
-
TYPO3-EXT-SA-2019-002: Multiple vulnerabilities in extension "typo3_forum" (typo3_forum)
Categories: DevelopmentAdvisory type: TYPO3 ExtensionsRead moreIt has been discovered that the extension "typo3_forum" (typo3_forum) is susceptible to Broken Access Control and Improper Filesystem Permissions.