TYPO3-PSA-2019-011: Possible Insecure Deserialization in Extbase Request Handling
It has been discovered that TYPO3 CMS can be vulnerable to insecure deserialization.
Read moreTYPO3-PSA-2019-010: Cross-Site Scripting Vulnerabilities in File Upload Handling
It has been discovered that TYPO3 is susceptible to cross-site scripting.
TYPO3 Version 10.2 — Treasure Hunting!
TYPO3 v10.2 is out now — the last sprint release of the year. A lot of functionality was developed during the TYPO3 Initiative Week (T3INIT19) and TYPO3 v10.2 contains some of these components. We are excited to see that we made a big step forward to shape the next LTS release.
TYPO3 Initiative Week—Insider Report
TYPO3 Initiative Week was introduced this year to bring together members of TYPO3 Initiatives to drive development forward. Core development is now organized into Strategic Initiatives where teams can focus on a targeted effort on one task. This week-long event provided a chance for everyone to connect across the initiatives.
Impressions of the Developer Days from the Documentation Team
In this post, the Documentation Team and contributors share their impressions from TYPO3 Developer Days 2019. They had sessions to talk about the state of documentation, to demonstrate how to contribute, and to generate new ideas and feedback.
TYPO3 9.5.11 and 8.7.29 maintenance releases published
The TYPO3 Community announces the versions 9.5.11 LTS and 8.7.29 LTS of the TYPO3 Enterprise Content Management System.
TYPO3-EXT-SA-2019-018: Remote Code Execution in extension "freeCap CAPTCHA" (sr_freecap)
It has been discovered that the extension "freeCap CAPTCHA" (sr_freecap) is susceptible to Remote Code Execution.
TYPO3-EXT-SA-2019-017: Multiple vulnerabilities in extension "SLUB: Event Registration" (slub_events)
It has been discovered that the extension "SLUB: Event Registration" (slub_events) is susceptible to Remote Code Execution, Unrestricted File Upload and Cross Site Scripting
TYPO3-EXT-SA-2019-016: Information Disclosure in extension "Direct Mail" (direct_mail)
It has been discovered that the extension "Direct Mail" (direct_mail) is susceptible to Information Disclosure.
TYPO3-EXT-SA-2019-015: SQL Injection in extension "URL redirect" (url_redirect)
It has been discovered that the extension "URL redirect" (url_redirect) is susceptible to SQL Injection.