CVE-2010-3662: SQL Injection
Published Nov 4, 2019
·Updated
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows SQL Injection on the backend.
Affected Software
9 affected componentsFixes available
composer/typo3/cms-backend>=4.4.0<4.4.1
4.4.1
composer/typo3/cms-backend>=4.3.0<4.3.4
4.3.4
composer/typo3/cms-backend>=4.2.0<4.2.13
4.2.13
composer/typo3/cms-backend<4.1.14
4.1.14
debian/typo3-src
Typo3 TYPO3>=4.4.0<4.4.1
Typo3 TYPO3>=4.3.0<4.3.4
Typo3 TYPO3<4.1.14
Typo3 TYPO3>=4.2.0<4.2.13
Event History
Nov 4, 2019
CVE Published
via MITRE·09:11 PM
Data Sourced
via MITRE·09:11 PM
Description
Apr 21, 2022
Advisory Published
via GitHub·01:57 AM
Frequently Asked Questions
1
What is the severity of CVE-2010-3662?
CVE-2010-3662 has been classified as a medium severity vulnerability due to its potential for SQL Injection.
2
How do I fix CVE-2010-3662?
To fix CVE-2010-3662, update TYPO3 to version 4.1.14 or higher, 4.2.13 or higher, 4.3.4 or higher, or 4.4.1.
3
Which TYPO3 versions are affected by CVE-2010-3662?
CVE-2010-3662 affects TYPO3 versions prior to 4.1.14, 4.2.13, 4.3.4, and 4.4.1.
4
What type of vulnerability is CVE-2010-3662 classified as?
CVE-2010-3662 is classified as an SQL Injection vulnerability in the TYPO3 backend.
5
Is there any workaround for CVE-2010-3662?
There are no known workarounds for CVE-2010-3662; updating to a fixed version is recommended.