7.5
CVSSv2

CVE-2017-7581

Published: 07/04/2017 Updated: 13/04/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 790
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in NewsController.php in the News module 5.3.2 and previous versions for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.

Vulnerable Product Search on Vulmon Subscribe to Product

news system project news system

Vendor Advisories

Check Point Reference: CPAI-2017-1721 Date Published: 19 Nov 2023 Severity: Critical ...