Skip to main navigation Skip to main content Skip to page footer

Security Advisories

All Advisories

Follow TYPO3 security advisories as soon as they are published by subscribing to the dedicated security RSS feed.

Subscribe to TYPO3 security advisories 

TYPO3-20051114-1: TYPO3 Security Bulletin

The file editor functionality in the TYPO3 Install Tool (menu option "Edit files in typo3conf/") has an option that reads "Make backup copy". If set, this will create a backup copy and append a "~" to the original file name. This leads to file names that may be delivered as text files by a web server. Thus, sensitive information (e.g. the content of localconf.php) may be disclosed.

Read more

TYPO3-20051107-1: chc_forum

A bug has been discovered in the "CHC Forum" (chc_forum) extension where some Javascript expressions are not properly caught when entered in forms. Thus, specially crafted entries may be used to inject malicious code.

Read more

TYPO3-20051010-10: TYPO3 Security Bulletin

A bug has been discovered in the "Front End News Submitter" (fe_news) where SQL injection is not safely prevented and thus malicious SQL commands are potentially possible. Since the RTE enabled version (fe_rtenews) is derived from fe_news, it is affected as well.

Read more