ZeroHour

CVE-2017-7581

PoC
CVSS 3.0
9.8 critical
EPSS
48%p99
Published
()
Modified
Description

SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.

Vendors
news system project
Products
news system
Weakness
CWE-89
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.