First published: Fri Jan 15 2010(Updated: )
SQL injection vulnerability in the MJS Event Pro (mjseventpro) extension 0.2.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TYPO3 mjseventpro | <=0.2.1 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0340 has a high severity rating due to its potential for remote SQL injection attacks.
To fix CVE-2010-0340, upgrade the MJS Event Pro extension to version 0.2.2 or later.
CVE-2010-0340 affects TYPO3 systems that are using the MJS Event Pro extension version 0.2.1 and earlier.
Yes, CVE-2010-0340 allows attackers to execute arbitrary SQL commands, potentially compromising the database.
While there may not be widely reported exploits, the vulnerability itself poses significant risk for exploitation if left unpatched.