Tag: Development
TYPO3-EXT-SA-2021-017: Multiple vulnerabilities in extension "pixx.io integration for TYPO3 (DAM)" (pixxio)
It has been discovered that the extension"pixx.io integration for TYPO3 (DAM)" (pixxio) is susceptible to Server-side request forgery, Remote Code Execution, Broken Access Control and vulnerable 3rd Party Components.
Read moreTYPO3-EXT-SA-2021-016: Denial of Service in extension "Code Highlight" (codehighlight)
It has been discovered that the extension "Code Highlight" (codehighlight) is susceptible to Denial of Service.
TYPO3-EXT-SA-2021-015: Cross-Site Scripting in extension "Google for Jobs" (google_for_jobs)
It has been discovered that the extension"Google for Jobs" (google_for_jobs) is susceptible to Cross-Site Scripting.
TYPO3 v11 Maintenance Release Schedule
TYPO3 v11 LTS was released in early October 2021, and it will have a predictable release plan for upcoming maintenance releases, as we have done since TYPO3 v7. Itβs a transparent schedule so everybody in the TYPO3 Community can know when to expect the next bug-fix and maintenance release.
TYPO3 11.5.2 maintenance release published
The version 11.5.2 of the TYPO3 Enterprise Content Management System has just been released.
TYPO3 11.5.1 maintenance release published
The version 11.5.1 of the TYPO3 Enterprise Content Management System has just been released.
TYPO3-CORE-SA-2021-015: HTTP Host Header Injection in Request Handling
It has been discovered that TYPO3 CMS is vulnerable to HTTP header injection.
TYPO3-CORE-SA-2021-014: Cross-Site-Request-Forgery in Backend URI Handling
It has been discovered that TYPO3 CMS is vulnerable to cross-site-request-forgery.
TYPO3 10.4.21 and 9.5.31 maintenance releases published
The versions 10.4.21 and 9.5.31 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3 v11 Codesprint Report
The TYPO3 Core Team Codesprint held on 12β14 August, 2021 was a big success. Here is a wrap-up of what happened during this hackathon, and what we achieved.