Description
SQL injection vulnerability in the WEC Map (wec_map) extension before 3.0.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
References (2)
Core 2
Core References
Patch, Vendor Advisory x_refsource_misc
http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2014-002/
Patch x_refsource_confirm
http://typo3.org/extensions/repository/view/wec_map
Scores
EPSS
0.0116
EPSS Percentile
64.0%
Details
CWE
CWE-89
Status
published
Products (5)
jbartels/wec-map
0 - 3.0.3Packagist
web-tp3/wec_map
0 - 3.0.3Packagist
wec_map_project/wec_map
3.0.0
wec_map_project/wec_map
3.0.1
wec_map_project/wec_map
< 3.0.2
Published
Oct 03, 2014
Tracked Since
Feb 18, 2026