Security Advisories
All Advisories
TYPO3-EXT-SA-2014-010: Several vulnerabilities in third party extensions
Several vulnerabilities have been found in the following third-party TYPO3 extensions: cwt_feedit, eu_ldap, flatmgr, jh_opengraphprotocol, ke_dompdf, lumophpinclude, news_pack, sb_akronymmanager, st_address_ma, weeaar_googlesitemap,. wt_directory
Mehr erfahrenTYPO3-EXT-SA-2014-009: Cross-Site Scripting in news
It has been discovered that the extension "News system" (news) is susceptible to Cross-Site Scripting
TYPO3-EXT-SA-2014-008: Cross-Site Scripting in gridelements
It has been discovered that the extension "Grid Elements" (gridelements) is susceptible to Cross-Site Scripting
TYPO3-CORE-SA-2014-001: Multiple Vulnerabilities in TYPO3 CMS
It has been discovered that TYPO3 CMS is vulnerable to Cross-Site Scripting, Insecure Unserialize, Improper Session Invalidation, Authentication Bypass, Information Disclosure and Host Spoofing.
TYPO3-EXT-SA-2014-007: Arbitrary code execution in extension "powermail" (powermail)
It has been discovered that the extension "powermail" (powermail) is susceptible to arbitrary code execution and Cross-Site Scripting
TYPO3-EXT-SA-2014-006: Captcha Bypass in extension "powermail" (powermail)
It has been discovered that the extension "powermail" (powermail) is susceptible to Captcha Bypass
TYPO3-EXT-SA-2014-005: Access Bypass in extensions "Yet Another Gallery" (yag) and "Tools for Extbase development" (pt_extbase)
It has been discovered that the extensions "Yet Another Gallery" (yag) and "Tools for Extbase development" (pt_extbase) are susceptible to Access Bypass
TYPO3-EXT-SA-2014-004: Mass Assignment in extension Direct Mail Subscription (direct_mail_subscription)
It has been discovered that the extension "Direct Mail Subscription" (direct_mail_subscription) is susceptible to Mass Assignment.
TYPO3-EXT-SA-2014-003: Insecure Unserialize in extension News (tt_news)
It has been discovered that the extension "News" (tt_news) is susceptible to Insecure Unserialize.
TYPO3-EXT-SA-2014-002: Several vulnerabilities in third party extensions
Several vulnerabilities have been found in the following third-party TYPO3 extensions: alpha_sitemap, femanager ke_stats, outstats, px_phpids, smarty, wec_map