Release date:
Updated on: 2013-07-01
Affected Systems:
TYPO3 SEO Pack for tt_news <= 1.3.3
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-4719
Typo3 is an open-source Content Management System (CMS) and Content Management Framework (CMF ).
SEO Pack for tt_news extension for TYPO3 does not properly filter certain inputs in SQL queries. A security vulnerability may cause arbitrary SQL code injection and further SQL queries.
<* Source: vendor
Link: http://secunia.com/advisories/53283
Http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2013-001/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
TYPO3
-----
TYPO3 has released a Security Bulletin (typo3-ext-sa-2013-001) and corresponding patches for this:
Typo3-ext-sa-2013-001: TYPO3-EXT-SA-2013-001: Several vulnerabilities in third party extensions
Link: http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2013-001/