Vulnerabilities (CVE)

Filtered by vendor News System Project Subscribe
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-7581 1 News System Project 1 News System 2023-12-10 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.