Description
SQL injection vulnerability in the Formhandler extension before 1.4.1 for TYPO3 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via unspecified vectors.
References (3)
Core 3
Core References
Patch, Vendor Advisory x_refsource_confirm
http://typo3.org/extensions/repository/view/formhandler
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/79670
Vendor Advisory x_refsource_misc
http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2012-012/
Scores
EPSS
0.0097
EPSS Percentile
58.1%
Details
CWE
CWE-89
Status
published
Products (19)
typoheads/formhandler
0.9.3
typoheads/formhandler
0.9.4
typoheads/formhandler
0.9.5
typoheads/formhandler
0.9.6
typoheads/formhandler
0.9.7
typoheads/formhandler
0.9.8
typoheads/formhandler
0.9.9
typoheads/formhandler
0.9.10
typoheads/formhandler
0.9.11
typoheads/formhandler
0.9.12
... and 9 more
Published
Jun 27, 2013
Tracked Since
Feb 18, 2026