First published: Fri Oct 10 2014(Updated: )
Multiple SQL injection vulnerabilities in the search function in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extension 2.14.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via the (1) education, (2) region, or (3) sector fields, as demonstrated by the tx_dmmjobcontrol_pi1[search][sector][] parameter to jobs/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kevin Renskers Dmmjobcontrol | <=2.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7201 has a high severity rating due to the potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2014-7201, upgrade the JobControl extension to a version newer than 2.14.0 that addresses these SQL injection vulnerabilities.
The fields affected by CVE-2014-7201 include education, region, and sector in the search function.
Users of TYPO3 with the JobControl extension version 2.14.0 or earlier are impacted by CVE-2014-7201.
CVE-2014-7201 is classified as a SQL injection vulnerability that can allow for unauthorized database queries.