QID 997946
Date Published: 2024-04-08
QID 997946: PHP (Composer) Security Update for typo3/cms (GHSA-gx4p-6w86-f8jx)
It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not properly replaced, could lead to a SQL Injection vulnerability. This issue can only be exploited if two or more parameters are bound to the query and at least two come from user input.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-gx4p-6w86-f8jx for updates and patch information.
Vendor References
- GHSA-gx4p-6w86-f8jx -
github.com/advisories/GHSA-gx4p-6w86-f8jx
CVEs related to QID 997946
Software Advisories
| Advisory ID | Software | Component | Link |
|---|