peter bassill · operator
$ cve CVE-2017-7581 JSON

CVE-2017-7581

9.8
CRITICAL · CVSS 3.0 · EPSS 48.4% (pctl 99)

Patch early

EPSS 48.4% — above the 10% action threshold.

Description

SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS48.43% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploitnone known
Published2017-04-07
Last modified2026-06-17

Affected (1)

VendorProduct
news system projectnews system

References

→ the Explorer  ·  watch your stack  ·  NVD