TYPO3 Extensions SQL Injection and Cross Site Scripting Vulnerabilities
Description
Multiple vulnerabilities have been identified in various TYPO3 extensions, which could be exploited by remote attackers to execute arbitrary SQL queries or scripting code. These issues are caused by input validation errors when processing user-supplied data, which could be exploited by malicious people to conduct cross site scripting and SQL injection attacks.
Vulnerable Products
Vulnerable Software: Commerce (commerce) version 0.9.6 and priorJobControl (dmmjobcontrol) version 1.15.4 and priorEconda Plugin (econda) version 0.0.2 and priorFrontend Users View (feusersview) version 0.1.6 and priorMannschaftsliste (kiddog_playerlist) version 1.0.3 and priorM1 Intern (m1_intern) version 1.0.0 and priorSimple survey (simplesurvey) version 1.7.0 and priorPage Improvements (sm_pageimprovements) version 1.1.0 and prior