CVE
- Id
- 104401
- CVE No.
- CVE-2017-7581
- Status
- Candidate
- Description
- SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.
- Phase
- Assigned (20170407)
- Votes
- None (candidate not yet proposed)
- Comments