Back

CRITICAL

It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not properly replaced, could lead to a SQL Injection vulnerability

Published Nov 25, 2019

Description

It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not properly replaced, could lead to a SQL Injection vulnerability. This issue can only be exploited if two or more parameters are bound to the query and at least two come from user input.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 25, 2019
Updated Aug 6, 2024
Reserved Sep 21, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-GX4P-6W86-F8JX