Description
SQL injection vulnerability in the backend module in the Developer Log (devlog) extension before 2.11.4 for TYPO3 allows remote editors to execute arbitrary SQL commands via unspecified vectors.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_misc
http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2015-011/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/75257
Patch x_refsource_confirm
http://typo3.org/extensions/repository/view/devlog
Scores
EPSS
0.0086
EPSS Percentile
54.8%
Details
CWE
CWE-89
Status
published
Products (1)
developer_log_project/developer_log
< 2.11.3
Published
Jun 16, 2015
Tracked Since
Feb 18, 2026