CVE-2009-4392

TYPO3 xds_staff <0.0.3 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the XDS Staff List (xds_staff) extension 0.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

References (1)

Core 1
Core References

Scores

EPSS 0.0037
EPSS Percentile 58.7%

Details

CWE
CWE-89
Status published
Products (1)
typo3/xds_staff < 0.0.3
Published Dec 22, 2009
Tracked Since Feb 18, 2026