Security Advisories
All Advisories
Follow TYPO3 security advisories as soon as they are published by subscribing to the dedicated security RSS feed.
TYPO3-20060902-1: tip-a-friend
A problem has been discovered with tip-a-friend being vulnerable to Cross-Site-Scripting (XSS)
TYPO3-20060512-1: TYPO3 Security Bulletin
Two problems (path traversal and SQL injection) have been discovered in the extension dam_downloads
SECURITY-BULLETIN-TYPO3-20060501-1-CHC-FORUM: Security Bulletin TYPO3-20060501-1: chc_forum
A weakness in the display of forum messages of chc_forum has been discovered that may be used to execute arbitrary SQL
TYPO3-20060501-1: TYPO3 Security Bulletin
A weakness in the display of forum messages of chc_forum has been discovered that may be used to execute arbitrary SQL
LAUNCH-OF-THE-NEW-EXTENSION-REPOSITORY: Launch of the new extension repository
After more than one year of hard work I am glad to announce the launch of TER2, our new extension repository. But that's not all: At the same time an improved and redesigned version of TYPO3.org goes online.
SECURITY-BULLETINS-IMPORTANT-SECURITY-ENHANCEMENTS-IN-TYPO3-381: Security Bulletins: Important Security Enhancements in TYPO3 3.8.1
Multiple TYPO3 Security Bulletins have been issued, all of which are addressed by the release of TYPO3 3.8.1.
TYPO3-20051114-7: TYPO3 Security Bulletin
Situations are imaginable where sensitive information gets stored in the fileadmin/_temp_/ directory. If misconfigured in your web server, this directory can be browsable and therefore expose that information.
TYPO3-20051114-6: TYPO3 Security Bulletin
Under special circumstances, setting config.baseURL (see typo3.org/documentation/document-library/doc_core_tsref/quot_CONFIG_quot/ ) to a numeric value ("1") could be used to spoof a malicious baseURL into your TYPO3 cache. It has now been decided to technically prevent this misconfiguration.
TYPO3-20051114-5: TYPO3 Security Bulletin
For convenience, the TYPO3 Install Tool provides a button sets the "encryptionKey" to a random value. It has been observed that only parts of the generated value are actually random. The overall key is therefore unique and -as of today- considered sufficiently secure. However, the effective key length is not the intended one.
TYPO3-20051114-4: TYPO3 Security Bulletin
In the past, a "Shift Reload" from the browser (AKA a GET request with the "no-cache" pragma set) cleared the TYPO3 cache of the requested page. This may be considered a potential target for Denial of Service attacks.