CVE-2009-3632: SQL Injection
SQL injection vulnerability in the traditional frontend editing feature in the Frontend Editing subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to execute arbitrary SQL commands via unspecified parameters.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3632?
CVE-2009-3632 has a high severity rating due to the potential for remote authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2009-3632?
To fix CVE-2009-3632, upgrade TYPO3 to version 4.1.13, 4.2.10, or 4.3beta2 or later.
What versions of TYPO3 are affected by CVE-2009-3632?
CVE-2009-3632 affects TYPO3 versions 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2.
Who can exploit CVE-2009-3632?
CVE-2009-3632 can be exploited by remote authenticated users who have access to the traditional frontend editing feature.
What type of vulnerability is CVE-2009-3632?
CVE-2009-3632 is classified as an SQL injection vulnerability.