CVE-2017-7581

SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.
References
Link Resource
https://www.ambionics.io/blog/typo3-news-module-sqli Exploit Patch Technical Description Third Party Advisory
https://www.ambionics.io/blog/typo3-news-module-sqli Exploit Patch Technical Description Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:news_system_project:news_system:*:*:*:*:*:typo3:*:*

History

21 Nov 2024, 03:32

Type Values Removed Values Added
References () https://www.ambionics.io/blog/typo3-news-module-sqli - Exploit, Patch, Technical Description, Third Party Advisory () https://www.ambionics.io/blog/typo3-news-module-sqli - Exploit, Patch, Technical Description, Third Party Advisory

Information

Published : 2017-04-07 19:59

Updated : 2025-04-20 01:37


NVD link : CVE-2017-7581

Mitre link : CVE-2017-7581

CVE.ORG link : CVE-2017-7581


JSON object : View

Products Affected

news_system_project

  • news_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')