TYPO3-PSA-2020-002: Protecting Install Tool with Sudo Mode
Accessing Install Tool via TYPO3 Backend requires password verification - known as Sudo Mode.
Read moreTYPO3-CORE-SA-2020-012: XML External Entity in Dashboard Widget
It has been discovered that TYPO3 CMS is susceptible to XML external entity processing.
TYPO3-CORE-SA-2020-011: Cleartext storage of session identifier
It has been discovered that TYPO3 CMS is susceptible to sensitive data exposure.
TYPO3-CORE-SA-2020-010: Cross-Site Scripting in Fluid view helpers
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting..
TYPO3-CORE-SA-2020-009: Cross-Site Scripting through Fluid view helper arguments
It has been discovered that the Fluid Engine is vulnerable to cross-site scripting.
TYPO3-EXT-SA-2020-020: Denial of Service in extension "Authenticator" (defbu_authenticator)
It has been discovered that the extension "Authenticator" (defbu_authenticator) is susceptible to Denial of Service.
TYPO3-EXT-SA-2020-019: Sensitive Data Exposure in extension "View frontend statistics" (view_statistics)
It has been discovered that the extension "View frontend statistics" (view_statistics) is susceptible to Sensitive Data Exposure.
TYPO3-EXT-SA-2020-018: Multiple vulnerabilities in extension "phpMyAdmin" (phpmyadmin)
It has been discovered that the extension "phpmyadmin" (phpmyadmin) is susceptible to SQL Injection and Cross-Site Scripting.
Successful TYPO3 Accessibility Sprint
The first remote accessibility sprint took place from 21st to 23rd of October 2020 and it was successful indeed. During these three productive days we focused on knowledge sharing, addressing open issues, and creating a practical checklist for developers. An accessible TYPO3 improves the experience of every user of TYPO3
Community Ombudsperson—What Are Your Thoughts?
Just before the Developer Days 2019, a small group was formed to look into setting up a formal body to ensure the wellbeing of everyone in the community—so-called ombudspersons. Now, we’re asking for your input.