Security Advisories (RSS Feed)

LevelInfoBetroffene VersionenLösung
Medium
September 17, 2024
TYPO3-EXT-SA-2024-007: Insecure Direct Object Reference in extension "powermail" (powermail)

It has been discovered that the extension "powermail" (powermail) is susceptible to Insecure Direct Object Reference.
7.5.0 and below
8.0.0 - 8.5.0
9.0.0 - 10.9.0
12.0.0 - 12.4.0
Updated versions 7.5.1
8.5.1
10.9.1 and 12.4.1 are  available from the TYPO3 extension manager
packagist and at  https://extensions.typo3.org/extension/download/powermail/7.5.1/ziphttps://extensions.typo3.org/extension/download/powermail/8.5.1/ziphttps://extensions.typo3.org/extension/download/powermail/10.9.1/ziphttps://extensions.typo3.org/extension/download/powermail/12.4.1/zipUsers of the extension are advised to update the extension as soon as possible.
Medium
August 27, 2024
TYPO3-EXT-SA-2024-006: Multiple vulnerabilities in "powermail" (powermail)

It has been discovered that the extension "powermail" (powermail) is susceptible to Insecure Direct Object Reference and Broken Access Control.
7.4.3 and below
8.0.0 - 8.4.2
9.0.0 - 10.8.2
12.0.0 - 12.3.5
Updated versions 7.5.0
8.5.0
10.9.0 and 12.4.0 are  available from the TYPO3 extension manager
packagist and at  https://extensions.typo3.org/extension/download/powermail/7.5.0/ziphttps://extensions.typo3.org/extension/download/powermail/8.5.0/ziphttps://extensions.typo3.org/extension/download/powermail/10.9.0/zip https://extensions.typo3.org/extension/download/powermail/12.4.0/zipUsers of the extension are advised to update the extension as soon as possible.
High
June 18, 2024
TYPO3-EXT-SA-2024-005: Multiple vulnerabilities in "Aimeos shop and e-commerce framework" (aimeos)

It has been discovered that the extension "Aimeos shop and e-commerce framework" (aimeos) is susceptible to Remote Code Execution and Insecure Direct Object Reference.
22.10.9 and below
23.0.0 - 23.10.6
24.0.0 - 24.4.1
Updated versions 22.10.10
23.10.7 and 24.4.2 are available from the TYPO3 extension manager
packagist and athttps://extensions.typo3.org/extension/download/aimeos/22.10.10/ziphttps://extensions.typo3.org/extension/download/aimeos/23.10.7/ziphttps://extensions.typo3.org/extension/download/aimeos/24.4.2/zipUsers of the extension are advised to update the extension as soon as possible.
Medium
June 18, 2024
TYPO3-EXT-SA-2024-004: Broken Access Control in "Integration of Friendly Captcha" (friendlycaptcha_official)

It has been discovered that the extension "Integration of Friendly Captcha" (friendlycaptcha_official) is susceptible to Broken Access Control.
0.1.3 and belowAn updated version 0.1.4 is  available from the TYPO3 extension manager
packagist and athttps://extensions.typo3.org/extension/download/friendlycaptcha_official/0.1.4/zipUsers of the extension are advised to update the extension as soon as possible.
Medium
June 18, 2024
TYPO3-EXT-SA-2024-003: Multiple vulnerabilities in "Events 2" (events2)

It has been discovered that the extension "Events 2" (events2) is susceptible to Cache Poisoning, Insecure Direct Object Reference and SQL wildcard injection.
8.3.7 and below
9.0.0 - 9.0.5
Updated versions 8.3.8 and 9.0.6 are available from the TYPO3 extension manager
packagist and athttps://extensions.typo3.org/extension/download/events2/8.3.8/ziphttps://extensions.typo3.org/extension/download/events2/9.0.6/zipUsers of the extension are advised to update the extension as soon as possible.
weitere links zur Sicherheit von Typo3: Alle Security Advisories (RSS Feed) Einträge zeigen |TYPO3 CMS |TYPO3 Extensions |Public Service Announcements |
typo3-coret3tsbase url hostname scheduler-status php-version db-version mask news t3adminer fontawesome_provider ke_search powermail gridelements typo3_console femanager rte_ckeditor_image simple_log404 translate_locallang container form_element_linked_checkbox numbered_pagination replacer secure_downloads solr solradmin bootstrap_grids displaydownloads extension_builder hcaptcha ke_search_premium mfa_email phpmyadmin rx_shariff solr_file_indexer static_info_tables sysfilemetadata_addfields t3gurom t3massnahmen tsoffer tt_address typo3db_legacy vhs
SecurityInfos von Typo3.org:
p2 | p7 | p10
p1 | p2 | p3 | p5 | p8 | p10
p6 | p8 | p9 | p10
9.5.4811.2.12https://www.leibniz-fli.de | FE | TYPO3-BE | Wikinewwashington3 / OK7.4.335.5.5-10.3.39-MariaDB-0ubuntu0.20.04.24.1.28.3.09.6.14.0.37.5.19.8.1
9.5.4811.2.12https://www.zfa-jena.de | FE | TYPO3-BE | Wikis10921 / OK7.4.33.65.7.35-384.1.25.8.6
10.4.3711.1.28https://www.kindersprachbruecke.de | FE | TYPO3-BE | Wiki7.4.33.6MySQL 5.7.356.4.58.5.24.0.38.5.110.4.36.7.71.4.0
10.4.3711.2.12https://www.timespin.de | FE | TYPO3-BE | Wikilive.timespin.de0 / OK7.4.3-4ubuntu2.235.5.5-10.3.39-MariaDB-0ubuntu0.20.04.26.6.18.5.2
10.4.4511.2.12https://awothueringen.de | FE | TYPO3-BE | Wikikm30718.keymachine.de2 / OK7.4.335.5.5-10.3.39-MariaDB-0ubuntu0.20.04.26.2.28.6.010.0.02.1.14.1.16.0.1
10.4.4511.2.12https://www.idz-jena.de | FE | TYPO3-BE | Wikis10402 / OK7.4.33.68.0.25-157.0.279.0.04.6.68.4.110.4.36.7.710.2.114.0.2
10.4.4511.2.12https://www.th-ern.net | FE | TYPO3-BE | Wikis11343 / OK7.4.33.65.7.35-385.1.18.3.04.6.68.5.110.4.36.7.75.1.2
11.5.3311.2.12https://www.dentinox.de | FE | TYPO3-BE | Wikiinfong-eu4146 / OK7.4.335.5.5-10.6.15-MariaDB-1:10.6.15+maria~deb11-log11.0.011.0.011.0.02.8.02.0.1
11.5.3711.2.12https://www.gurom.de | FE | TYPO3-BE | Wikiwww521.your-server.de4 / OK7.4.335.5.5-10.5.26-MariaDB-0+deb11u28.3.1012.0.11.0.37.3.01.1.2.TS-Patched11.0.1211.1.411.1.41.2.0
11.5.3711.2.12https://www.innovent-jena.de | FE | TYPO3-BE | Wikiwww498.your-server.de5 / OK8.2.2310.11.6-MariaDB-hetzner18.0.5_heiko_update_klappte_leider_nicht11.4.212.0.11.0.35.5.010.8.13.0.311.5.5
11.5.3911.2.12https://www.uniwind.org | FE | TYPO3-BE | Wikis11242 / OK8.1.295.7.35-388.3.1011.4.212.0.11.0.310.8.18.1.12.3.6
12.4.1512.2.2https://www.kv-thueringen.de | FE | TYPO3-BE | Wikiwww507.your-server.de8 / OK8.2.2310.5.26-MariaDB-0+deb11u28.3.1011.4.212.0.11.0.35.5.08.1.02.0.05.0.412.2.5
12.4.1512.2.2https://www.varys.de | FE | TYPO3-BE | Wikiwww527.your-server.de5 / OK8.2.2310.5.26-MariaDB-0+deb11u28.3.1011.4.212.0.11.0.35.5.012.4.18.1.02.3.62.0.06.0.312.2.1
12.4.1912.2.7https://sgs-institut-fresenius.de | FE | TYPO3-BE | Wikijones12 / OK8.2.2210.3.39-MariaDB-0ubuntu0.20.04.28.3.1111.4.212.0.11.0.312.0.2_TS-Patched1.2.0_TS-Patched3.1.04.0.012.0.52.0.1
12.4.1912.2.7https://sgs-proderm.de | FE | TYPO3-BE | Wikijones9 / OK8.2.2210.3.39-MariaDB-0ubuntu0.20.04.28.3.1111.4.212.0.11.0.312.0.2_TS-Patched1.2.2_TS-Patched3.1.04.0.012.0.52.0.12.2.01.0.53.0.07.0.6