Skip to main navigation Skip to main content Skip to page footer

Multiple vulnerabilities in extension T3BLOG (t3blog)

It has been discovered that the extension T3BLOG (t3blog) is vulnerable to SQL Injection and Cross–Site Scripting.

Release Date: February 1, 2010

Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.

Affected Versions: Version 0.6.2 and all versions below

Vulnerability Type: Multiple SQL Injection and Cross–Site Scripting vulnerabilities

Severity: Critical

Problem Description: The TYPO3 extension t3blog fails to sanitize parameters provided by the user through HTML forms. Therefore both SQL Injection and Cross–Site Scripting are possible in Frontend and Backend.

Solution: An updated version 0.8.0 is available from the TYPO3 extension manager and at http://typo3.org/extensions/repository/view/t3blog/0.8.0/. Users of the extension are advised to update the extension as soon as possible.

Credits: Credits go to TYPO3 Security Team Member Marcus Krause who discovered and reported the issues and to TYPO3 Security Team Member Dmitry Dulepov who fixed the issues.

 

General advice: Follow the recommendations that are given in the TYPO3 Security Cookbook. Please subscribe to the typo3-announce mailing list to receive future Security Bulletins via E-mail.