CVE-2017-7581
9.8
CRITICAL · CVSS 3.0 · EPSS 48.4% (pctl 99)
Patch early
EPSS 48.4% — above the 10% action threshold.
Description
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 48.43% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-04-07 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| news system project | news system |
References
→ the Explorer · watch your stack · NVD