WEC Discussion for TYPO3 Cross Site Scripting and SQL Injection Issues
Description
Multiple vulnerabilities have been identified in WEC Discussion Forum (extension for TYPO3), which could be exploited by attackers to manipulate or disclose certain data. These issues are caused by unspecified input validation errors, which could allow cross site scripting and SQL injection attacks.
Vulnerable Products
Vulnerable Software: WEC Discussion Forum (extension for TYPO3) version 1.7.0 and prior