Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Matthias Hunstock

#17948of 53,635
15Total CVSS
Vulnerabilities · 2
High
2
PT-2019-6673
7.5
2019-11-25
Typo3 · Typo3 Core Wec Discussion Extension · CVE-2011-3584
**Name of the Vulnerable Software and Affected Versions** TYPO3 Core wec discussion extension versions prior to 2.1.1 **Description** The issue is related to SQL Injection due to improper sanitation of user-supplied input. This allows for potential exploitation by injecting malicious SQL code. **Recommendations** For versions prior to 2.1.1, update to version 2.1.1 or later to resolve the issue. As a temporary workaround, consider restricting user input to minimize the risk of SQL Injection until a patch is applied.
PT-2011-3322
7.5
2011-04-19
Typo3 · Typo3 Wec Discussion Forum · CVE-2011-1722
**Name of the Vulnerable Software and Affected Versions** TYPO3 WEC Discussion Forum (wec discussion) extension versions 2.1.0 and earlier **Description** The issue allows remote attackers to execute arbitrary SQL commands, which has been exploited in the wild. **Recommendations** For versions 2.1.0 and earlier, update to a version later than 2.1.0 to resolve the issue.