Description
SQL injection vulnerability in the init function in MK-AnydropdownMenu (mk_anydropdownmenu) extension 0.3.28 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
References (3)
Core 3
Core References
Patch x_refsource_confirm
http://typo3.org/extensions/repository/view/mk_anydropdownmenu/0.4.0/info/ChangeLog/
Patch, Vendor Advisory x_refsource_confirm
http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/
Patch x_refsource_confirm
http://typo3.org/extensions/repository/view/mk_anydropdownmenu/0.4.0/
Scores
EPSS
0.0105
EPSS Percentile
60.8%
Details
CWE
CWE-89
Status
published
Products (8)
matthias_karr/mk_anydropdownmenu
0.3.10
matthias_karr/mk_anydropdownmenu
0.3.12
matthias_karr/mk_anydropdownmenu
0.3.13
matthias_karr/mk_anydropdownmenu
0.3.23
matthias_karr/mk_anydropdownmenu
0.3.25
matthias_karr/mk_anydropdownmenu
0.3.26
matthias_karr/mk_anydropdownmenu
0.3.27
matthias_karr/mk_anydropdownmenu
< 0.3.28
Published
Jan 15, 2010
Tracked Since
Feb 18, 2026