PT-2014-5484 · Typo3 · Si Bibtex Extension+1

Publicado

2014-05-16

·

Atualizado

2018-10-09

·

CVE-2014-3759

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TYPO3 si bibtex extension version 0.2.3
Description The issue concerns SQL injection vulnerabilities in the search and list functionality of the si bibtex extension for TYPO3, allowing remote attackers to execute arbitrary SQL commands.
Recommendations For version 0.2.3, consider disabling the search and list functionality in the si bibtex extension until a patch is available. Restrict access to the si bibtex extension to minimize the risk of exploitation.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3759

Produtos afetados

Typo3
Si Bibtex Extension