TYPO3 Sicherheitshinweise

Auf dieser Seite finden Sie die offiziellen TYPO3-Sicherheitshinweise in englischer Sprache.
Die einzelnen Beiträge verweisen auf den jeweiligen Original-Beitrag auf typo3.org.

TYPO3-EXT-SA-2023-007: Broken Access Control in extension "hCaptcha for EXT:form" (hcaptcha)
TYPO3-CORE-SA-2023-004: Cross-Site Scripting in CKEditor4 WordCount Plugin
TYPO3-CORE-SA-2023-003: Information Disclosure due to Out-of-scope Site Resolution
TYPO3-CORE-SA-2023-002: By-passing Cross-Site Scripting Protection in HTML Sanitizer
TYPO3-EXT-SA-2023-006: Multiple vulnerabilities in extension "Canto Extension" (canto_extension)
TYPO3-EXT-SA-2023-005: SQL Injection in extension "ipandlanguageredirect" (ipandlanguageredirect)
TYPO3-EXT-SA-2023-004: Cross-Site Scripting in extension "Faceted Search" (ke_search)
TYPO3-EXT-SA-2023-003: Cross-Site Scripting in extension "Fluid Components" (fluid_components)
TYPO3-EXT-SA-2023-002: Persisted Cross-Site Scripting in extension "Forms Export" (frp_form_answers)
TYPO3-CORE-SA-2023-001: Persisted Cross-Site Scripting in Frontend Rendering
TYPO3-PSA-2023-001: Important Security-Bulletin Pre-Announcement
TYPO3-EXT-SA-2023-001: Broken Access Control in extension "femanager" (femanager)
TYPO3-EXT-SA-2022-018: Multiple vulnerabilities in extension "Master-Quiz" (fp_masterquiz)
TYPO3-EXT-SA-2022-017: Multiple vulnerabilities in extension "Newsletter subscriber management" (fp_newsletter)
TYPO3-EXT-SA-2022-016: Insufficient Session Expiration after Password Change in extension "Change password for frontend users" (fe_change_pwd)
TYPO3-CORE-SA-2022-017: By-passing Cross-Site Scripting Protection in HTML Sanitizer
TYPO3-CORE-SA-2022-016: Sensitive Information Disclosure via YAML Placeholder Expressions in Site Configuration
TYPO3-CORE-SA-2022-015: Arbitrary Code Execution via Form Framework
TYPO3-CORE-SA-2022-014: Insufficient Session Expiration after Password Reset
TYPO3-CORE-SA-2022-013: Weak Authentication in Frontend Login
TYPO3-CORE-SA-2022-012: Denial of Service in Page Error Handling
TYPO3-EXT-SA-2022-015: Broken Access Control in extension "femanager" (femanager)
TYPO3-CORE-SA-2022-011: By-passing Cross-Site Scripting Protection in HTML Sanitizer
TYPO3-CORE-SA-2022-010: Cross-Site Scripting in <f:asset.css> view helper
TYPO3-CORE-SA-2022-009: Stored Cross-Site Scripting via FileDumpController
TYPO3-CORE-SA-2022-008: Missing check for expiration time of password reset token for backend users
TYPO3-CORE-SA-2022-007: User Enumeration via Response Timing
TYPO3-CORE-SA-2022-006: Denial of Service in Page Error Handling
TYPO3-EXT-SA-2022-014: SQL Injection in extension "LUX - TYPO3 Marketing Automation" (lux)
TYPO3-CORE-SA-2022-005: Insufficient Session Expiration in Admin Tool