CVE-2013-1842: SQL Injection
SQL injection vulnerability in the Extbase Framework in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to "the Query Object Model and relation values."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1842?
CVE-2013-1842 is a critical SQL injection vulnerability that enables remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2013-1842?
To fix CVE-2013-1842, upgrade TYPO3 to versions 6.0.3, 4.7.9, 4.6.17, or 4.5.24 or later.
Which TYPO3 versions are affected by CVE-2013-1842?
CVE-2013-1842 affects TYPO3 versions 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3.
Can CVE-2013-1842 lead to data breaches?
Yes, CVE-2013-1842 can lead to unauthorized access to the database, potentially resulting in data breaches.
Is CVE-2013-1842 unique to TYPO3 or common in other systems?
While CVE-2013-1842 is specific to TYPO3, SQL injection vulnerabilities are commonly found in various web applications.