Author: Torben Hansen
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2019-020: CSRF in extension "Change password for frontend users" (fe_change_pwd)
-
Torben Hansen
It has been discovered that the extension "Change password for frontend users" (fe_change_pwd) is susceptible to Cross-Site-Request-Forgery (CSRF).
Read more- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2019-019: Multiple vulnerabilities in extension "MKSamlAuth" (mksamlauth)
-
Torben Hansen
It has been discovered that the extension "MKSamlAuth" (mksamlauth) is susceptible to Broken Authentication and Authentication Bypass.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2019-018: Remote Code Execution in extension "freeCap CAPTCHA" (sr_freecap)
-
Torben Hansen
It has been discovered that the extension "freeCap CAPTCHA" (sr_freecap) is susceptible to Remote Code Execution.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2019-017: Multiple vulnerabilities in extension "SLUB: Event Registration" (slub_events)
-
Torben Hansen
It has been discovered that the extension "SLUB: Event Registration" (slub_events) is susceptible to Remote Code Execution, Unrestricted File Upload and Cross Site Scripting
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2019-016: Information Disclosure in extension "Direct Mail" (direct_mail)
-
Torben Hansen
It has been discovered that the extension "Direct Mail" (direct_mail) is susceptible to Information Disclosure.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2019-015: SQL Injection in extension "URL redirect" (url_redirect)
-
Torben Hansen
It has been discovered that the extension "URL redirect" (url_redirect) is susceptible to SQL Injection.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2019-014: Multiple vulnerabilities in extension "phpMyAdmin" (phpmyadmin)
-
Torben Hansen
It has been discovered that the extension "phpMyAdmin" (phpmyadmin) is susceptible to Arbitrary file read and SQL injection.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2019-013: SQL Injection in extension "comsolit Suggest" (comsolit_suggest)
-
Torben Hansen
It has been discovered that the extension "comsolit Suggest" (comsolit_suggest) is susceptible to SQL Injection.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2019-012: Arbitrary file Upload in extension "Yet Another Gallery" (yag)
-
Torben Hansen
It has been discovered that the extension "Yet Another Gallery" (yag) is susceptible to Arbitrary File Upload.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2019-011: SQL Injection in extension "Event Calender" (pits_wd_calender)
-
Torben Hansen
It has been discovered that the extension "Event Calender" (pits_wd_calender) is susceptible to SQL Injection.