| Level | Info | Betroffene Versionen | Lösung |
|---|---|---|---|
| MediumSeptember 17, 2024 | TYPO3-EXT-SA-2024-007: Insecure Direct Object Reference in extension "powermail" (powermail) It has been discovered that the extension "powermail" (powermail) is susceptible to Insecure Direct Object Reference. | 7.5.0 and below 8.0.0 - 8.5.0 9.0.0 - 10.9.0 12.0.0 - 12.4.0 | Updated versions 7.5.1 8.5.1 10.9.1 and 12.4.1 are available from the TYPO3 extension manager packagist and at https://extensions.typo3.org/extension/download/powermail/7.5.1/ziphttps://extensions.typo3.org/extension/download/powermail/8.5.1/ziphttps://extensions.typo3.org/extension/download/powermail/10.9.1/ziphttps://extensions.typo3.org/extension/download/powermail/12.4.1/zipUsers of the extension are advised to update the extension as soon as possible. |
| MediumAugust 27, 2024 | TYPO3-EXT-SA-2024-006: Multiple vulnerabilities in "powermail" (powermail) It has been discovered that the extension "powermail" (powermail) is susceptible to Insecure Direct Object Reference and Broken Access Control. | 7.4.3 and below 8.0.0 - 8.4.2 9.0.0 - 10.8.2 12.0.0 - 12.3.5 | Updated versions 7.5.0 8.5.0 10.9.0 and 12.4.0 are available from the TYPO3 extension manager packagist and at https://extensions.typo3.org/extension/download/powermail/7.5.0/ziphttps://extensions.typo3.org/extension/download/powermail/8.5.0/ziphttps://extensions.typo3.org/extension/download/powermail/10.9.0/zip https://extensions.typo3.org/extension/download/powermail/12.4.0/zipUsers of the extension are advised to update the extension as soon as possible. |
| HighJune 18, 2024 | TYPO3-EXT-SA-2024-005: Multiple vulnerabilities in "Aimeos shop and e-commerce framework" (aimeos) It has been discovered that the extension "Aimeos shop and e-commerce framework" (aimeos) is susceptible to Remote Code Execution and Insecure Direct Object Reference. | 22.10.9 and below 23.0.0 - 23.10.6 24.0.0 - 24.4.1 | Updated versions 22.10.10 23.10.7 and 24.4.2 are available from the TYPO3 extension manager packagist and athttps://extensions.typo3.org/extension/download/aimeos/22.10.10/ziphttps://extensions.typo3.org/extension/download/aimeos/23.10.7/ziphttps://extensions.typo3.org/extension/download/aimeos/24.4.2/zipUsers of the extension are advised to update the extension as soon as possible. |
| MediumJune 18, 2024 | TYPO3-EXT-SA-2024-004: Broken Access Control in "Integration of Friendly Captcha" (friendlycaptcha_official) It has been discovered that the extension "Integration of Friendly Captcha" (friendlycaptcha_official) is susceptible to Broken Access Control. | 0.1.3 and below | An updated version 0.1.4 is available from the TYPO3 extension manager packagist and athttps://extensions.typo3.org/extension/download/friendlycaptcha_official/0.1.4/zipUsers of the extension are advised to update the extension as soon as possible. |
| MediumJune 18, 2024 | TYPO3-EXT-SA-2024-003: Multiple vulnerabilities in "Events 2" (events2) It has been discovered that the extension "Events 2" (events2) is susceptible to Cache Poisoning, Insecure Direct Object Reference and SQL wildcard injection. | 8.3.7 and below 9.0.0 - 9.0.5 | Updated versions 8.3.8 and 9.0.6 are available from the TYPO3 extension manager packagist and athttps://extensions.typo3.org/extension/download/events2/8.3.8/ziphttps://extensions.typo3.org/extension/download/events2/9.0.6/zipUsers of the extension are advised to update the extension as soon as possible. |
typo3-core t3tsbase ↓ url ↓ hostname ↓ scheduler-status ↓ php-version ↓ db-version ↓ mask ↓ news ↓ t3adminer ↓ fontawesome_provider ↓ ke_search ↓ powermail ↓ gridelements ↓ typo3_console ↓ femanager ↓ rte_ckeditor_image ↓ simple_log404 ↓ translate_locallang ↓ container ↓ form_element_linked_checkbox ↓ numbered_pagination ↓ replacer ↓ secure_downloads ↓ solr ↓ solradmin ↓ bootstrap_grids ↓ displaydownloads ↓ extension_builder ↓ hcaptcha ↓ ke_search_premium ↓ mfa_email ↓ phpmyadmin ↓ rx_shariff ↓ solr_file_indexer ↓ static_info_tables ↓ sysfilemetadata_addfields ↓ t3gurom ↓ t3massnahmen ↓ tsoffer ↓ tt_address ↓ typo3db_legacy ↓ vhs ↓ SecurityInfos von Typo3.org: 9.5.48 11.2.12 https://www.leibniz-fli.de | FE | TYPO3-BE | Wiki newwashington 3 / OK 7.4.33 5.5.5-10.3.39-MariaDB-0ubuntu0.20.04.2 4.1.2 8.3.0 9.6.1 4.0.3 7.5.1 9.8.1 9.5.48 11.2.12 https://www.zfa-jena.de | FE | TYPO3-BE | Wiki s1092 1 / OK 7.4.33.6 5.7.35-38 4.1.2 5.8.6 10.4.37 11.1.28 https://www.kindersprachbruecke.de | FE | TYPO3-BE | Wiki 7.4.33.6 MySQL 5.7.35 6.4.5 8.5.2 4.0.3 8.5.1 10.4.3 6.7.7 1.4.0 10.4.37 11.2.12 https://www.timespin.de | FE | TYPO3-BE | Wiki live.timespin.de 0 / OK 7.4.3-4ubuntu2.23 5.5.5-10.3.39-MariaDB-0ubuntu0.20.04.2 6.6.1 8.5.2 10.4.45 11.2.12 https://awothueringen.de | FE | TYPO3-BE | Wiki km30718.keymachine.de 2 / OK 7.4.33 5.5.5-10.3.39-MariaDB-0ubuntu0.20.04.2 6.2.2 8.6.0 10.0.0 2.1.1 4.1.1 6.0.1 10.4.45 11.2.12 https://www.idz-jena.de | FE | TYPO3-BE | Wiki s1040 2 / OK 7.4.33.6 8.0.25-15 7.0.27 9.0.0 4.6.6 8.4.1 10.4.3 6.7.7 10.2.1 14.0.2 10.4.45 11.2.12 https://www.th-ern.net | FE | TYPO3-BE | Wiki s1134 3 / OK 7.4.33.6 5.7.35-38 5.1.1 8.3.0 4.6.6 8.5.1 10.4.3 6.7.7 5.1.2 11.5.33 11.2.12 https://www.dentinox.de | FE | TYPO3-BE | Wiki infong-eu414 6 / OK 7.4.33 5.5.5-10.6.15-MariaDB-1:10.6.15+maria~deb11-log 11.0.0 11.0.0 11.0.0 2.8.0 2.0.1 11.5.37 11.2.12 https://www.gurom.de | FE | TYPO3-BE | Wiki www521.your-server.de 4 / OK 7.4.33 5.5.5-10.5.26-MariaDB-0+deb11u2 8.3.10 12.0.1 1.0.3 7.3.0 1.1.2.TS-Patched 11.0.12 11.1.4 11.1.4 1.2.0 11.5.37 11.2.12 https://www.innovent-jena.de | FE | TYPO3-BE | Wiki www498.your-server.de 5 / OK 8.2.23 10.11.6-MariaDB-hetzner1 8.0.5_heiko_update_klappte_leider_nicht 11.4.2 12.0.1 1.0.3 5.5.0 10.8.1 3.0.3 11.5.5 11.5.39 11.2.12 https://www.uniwind.org | FE | TYPO3-BE | Wiki s1124 2 / OK 8.1.29 5.7.35-38 8.3.10 11.4.2 12.0.1 1.0.3 10.8.1 8.1.1 2.3.6 12.4.15 12.2.2 https://www.kv-thueringen.de | FE | TYPO3-BE | Wiki www507.your-server.de 8 / OK 8.2.23 10.5.26-MariaDB-0+deb11u2 8.3.10 11.4.2 12.0.1 1.0.3 5.5.0 8.1.0 2.0.0 5.0.4 12.2.5 12.4.15 12.2.2 https://www.varys.de | FE | TYPO3-BE | Wiki www527.your-server.de 5 / OK 8.2.23 10.5.26-MariaDB-0+deb11u2 8.3.10 11.4.2 12.0.1 1.0.3 5.5.0 12.4.1 8.1.0 2.3.6 2.0.0 6.0.3 12.2.1 12.4.19 12.2.7 https://sgs-institut-fresenius.de | FE | TYPO3-BE | Wiki jones 12 / OK 8.2.22 10.3.39-MariaDB-0ubuntu0.20.04.2 8.3.11 11.4.2 12.0.1 1.0.3 12.0.2_TS-Patched 1.2.0_TS-Patched 3.1.0 4.0.0 12.0.5 2.0.1 12.4.19 12.2.7 https://sgs-proderm.de | FE | TYPO3-BE | Wiki jones 9 / OK 8.2.22 10.3.39-MariaDB-0ubuntu0.20.04.2 8.3.11 11.4.2 12.0.1 1.0.3 12.0.2_TS-Patched 1.2.2_TS-Patched 3.1.0 4.0.0 12.0.5 2.0.1 2.2.0 1.0.5 3.0.0 7.0.6