CVE-2017-7581
07.04.2017, 19:59
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.
| Vendor | Product | Version |
|---|---|---|
| news_system_project | news_system | 𝑥 ≤ 5.3.2 |
𝑥
= Vulnerable software versions