CVE-2011-3584: SQL Injection
Published Nov 25, 2019
·Updated
The TYPO3 Core wecdiscussion extension before 2.1.1 is vulnerable to SQL Injection due to improper sanitation of user-supplied input.
Affected Software
2 affected components
debian/typo3-src
Guidestar Wec Discussion Forum Typo3<2.1.1
Event History
Nov 25, 2019
CVE Published
via MITRE·11:31 PM
Data Sourced
via MITRE·11:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this TYPO3 Core extension?
The vulnerability ID of this TYPO3 Core extension is CVE-2011-3584.
2
What is the severity of CVE-2011-3584?
The severity of CVE-2011-3584 is critical with a CVSS score of 9.8.
3
What is the affected software of CVE-2011-3584?
The affected software of CVE-2011-3584 is the TYPO3 Core wec_discussion extension before version 2.1.1.
4
What is the description of CVE-2011-3584?
CVE-2011-3584 is a SQL Injection vulnerability in the TYPO3 Core wec_discussion extension before version 2.1.1, caused by improper sanitation of user-supplied input.
5
How can I fix CVE-2011-3584?
To fix CVE-2011-3584, update the TYPO3 Core wec_discussion extension to version 2.1.1 or later.