Author: Torben Hansen
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2022-008: Multiple vulnerabilities in extension "Adminer" (t3adminer)
-
Torben Hansen
It has been discovered that the extension "Adminer" (t3adminer) is susceptible to Server-side request forgery and Cross-Site Scripting.
Read more- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2022-007: SQL Injection in extension "One is Enough Library" (oelib)
-
Torben Hansen
It has been discovered that the extension "One is Enough Library" (oelib) is susceptible to SQL Injection.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2022-006: SQL Injection in extension "Seminar Manager" (seminars)
-
Torben Hansen
It has been discovered that the extension "Seminar Manager" (seminars) is susceptible to SQL Injection.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2022-005: Remote Code Execution in extension "Job portal" (psvneo_jobfair)
-
Torben Hansen
It has been discovered that the extension "Job portal" (psvneo_jobfair) is susceptible to Remote Code Execution.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2022-004: File Content Injection in extension "Hardcoded text to Locallang" (mqk_locallangtools)
-
Torben Hansen
It has been discovered that the extension "Hardcoded text to Locallang" (mqk_locallangtools) is susceptible to File Content Injection.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2022-003: Insecure direct object reference in extension "Varnishcache" (varnishcache)
-
Torben Hansen
It has been discovered that the extension "Varnishcache" (varnishcache) is susceptible to Insecure direct object reference.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2022-002: Cross-Site Scripting in extension "Bookdatabase" (extbookdatabase)
-
Torben Hansen
It has been discovered that the extension "Bookdatabase" (extbookdatabase) is susceptible to Cross-Site Scripting.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2022-001: Server-side request forgery in extension "Kitodo.Presentation" (dlf)
-
Torben Hansen
It has been discovered that the extension "Kitodo.Presentation" (dlf) is susceptible to Server-side request forgery.
- Developer & Technology
- Product Updates & Roadmap
- Public Service Announcement
TYPO3-PSA-2021-004: Statement on Recent log4j/log4shell Vulnerabilities (CVE-2021-44228)
-
Torben Hansen
Components of TYPO3 CMS are based on PHP and are therefore not directly affected by the recent log4j vulnerabilities. However, additional services used in web application scenarios may be affected.
- Developer & Technology
- TYPO3 Extensions
TYPO3-EXT-SA-2021-018: Sensitive Data Exposure in extension "Job Fair" (jobfair)
-
Torben Hansen
It has been discovered that the extension "Job Fair" (jobfair) is susceptible to Sensitive Data Exposure.