TYPO3-EXT-SA-2018-004: Cross-site scripting vulnerability in extension "Powermail" (powermail)
It has been discovered that the extension "Powermail" (powermail) is susceptible to Cross-Site Scripting.
Read moreTYPO3-EXT-SA-2018-003: Environment Variable Injection in extension "Amazon AWS S3 FAL driver (CDN)" (aus_driver_amazon_s3)
It has been discovered that the extension "Amazon AWS S3 FAL driver (CDN)" (aus_driver_amazon_s3) is susceptible to Environment Variable Injection.
TYPO3-EXT-SA-2018-002: Missing Access Check in extension "Register to tt_address" (registeraddress)
It has been discovered that the extension "Register to tt_address" (registeraddress) has a missing access check.
TYPO3-EXT-SA-2018-001: Cross-Site Scripting in extension "Heise Shariff" (rx_shariff)
It has been discovered that the extension "Heise Shariff" (rx_shariff) is susceptible to Cross-Site Scripting.
TYPO3 9.3.3, 8.7.18 and 7.6.31 released
The TYPO3 Community announces the versions 9.3.3, 8.7.18 LTS and 7.6.31 LTS of the TYPO3 Enterprise Content Management System.
A new structure for the TYPO3 Core team
The TYPO3 Core Team started a restructuring process led by Oliver Hader and me. Over the following weeks working modes, processes and current requirements will be evaluated and ultimately result in a new and more sustainable team structure with an efficient working mode.
TYPO3-CORE-SA-2018-004: Insecure Deserialization in TYPO3 CMS
It has been discovered, that TYPO3 CMS is vulnerable to Insecure Deserialization.
TYPO3-CORE-SA-2018-003: Privilege Escalation & SQL Injection in TYPO3 CMS
It has been discovered, that TYPO3 CMS is vulnerable to Privilege Escalation and SQL Injection.
TYPO3-CORE-SA-2018-001: Authentication Bypass in TYPO3 CMS
It has been discovered, that TYPO3 CMS is vulnerable to Authentication Bypass.
TYPO3 9.3.1, 8.7.17 and 7.6.30 security releases published
The TYPO3 Community announces the versions 9.3.1, 8.7.17 LTS and 7.6.30 LTS of the TYPO3 Enterprise Content Management System.