Release date:
Updated on: 2013-07-01
Affected Systems:
TYPO3 RSS feed from records <= 1.0.0
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-4721
Typo3 is an open-source Content Management System (CMS) and Content Management Framework (CMF ).
TYPO3's RSS feed from records extension has the SQL injection vulnerability, which allows remote attackers to send specially crafted SQL statements to unspecified scripts, this vulnerability allows you to view, add, modify, or delete information in a backend database and execute any SQL command.
<* Source: vendor
Link: http://xforce.iss.net/xforce/xfdb/82218
Http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2013-005/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
TYPO3
-----
TYPO3 has released a Security Bulletin (typo3-ext-sa-2013-005) and corresponding patches for this:
Typo3-ext-sa-2013-005: TYPO3-EXT-SA-2013-005: Several vulnerabilities in third party extensions
Link: http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2013-005/