PoC Index

CVE-2017-7581

CRITICAL 9.8EPSS 48.4%

SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
48.43% chance of exploitation in the next 30 days, 99th percentile
Published
2017-04-07
Updated
2024-08-05

Proof-of-concept exploits (1)

Metasploit modules (1)

References

Related