QID 996683
Date Published: 2024-01-15
QID 996683: PHP (Composer) Security Update for typo3/cms (GHSA-947m-vgqc-x6v4)
SQL injection vulnerability in the Backend History module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 Due to missing encoding of user input, the history module is susceptible to SQL Injection and Cross-Site Scripting. A valid backend login is required to exploit this vulnerability.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-947m-vgqc-x6v4 for updates and patch information.
Vendor References
- GHSA-947m-vgqc-x6v4 -
github.com/advisories/GHSA-947m-vgqc-x6v4
CVEs related to QID 996683
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-947m-vgqc-x6v4 | typo3/cms |
|