SQL injection vulnerability in the News system (news) extension before 1.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-4598 | News system (news) extension for TYPO3 vulnerable to SQL Injection |
Github GHSA |
GHSA-rg6g-v4xm-g49q | News system (news) extension for TYPO3 vulnerable to SQL Injection |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T16:52:27.024Z
Reserved: 2013-07-01T00:00:00.000Z
Link: CVE-2013-4748
No data.
Status : Deferred
Published: 2013-07-01T23:55:01.123
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-4748
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA