[Ticket#201707115760000029] Vulnerabilities in multiple third party TYPO3 CMS extensions
Dear TYPO3 users, several vulnerabilities have been found in the following third party TYPO3 extensions: "Faceted Search" (ke_search) "Maag Sendmail" (maag_sendmail) "AH Sendmail" (ah_sendmail) "PHPMailer" (bb_phpmailer) "Content Rating Extbase" (content_rating_extbase) For further information on the issues, please read the related advisories TYPO3-EXT-SA-2017-003, TYPO3-EXT-SA-2017-004, TYPO3-EXT-SA-2017-005, TYPO3-EXT-SA-2017-006 and TYPO3-EXT-SA-2017-007 which were published today: TYPO3-EXT-SA-2017-003: SQL Injection in extension "Faceted Search" (ke_search) [1]https://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2017-003/ TYPO3-EXT-SA-2017-004: Remote Code Execution in extension "Maag Sendmail" (maag_sendmail) [2]https://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2017-004/ TYPO3-EXT-SA-2017-005: Remote Code Execution in extension "AH Sendmail" (ah_sendmail) [3]https://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2017-005/ TYPO3-EXT-SA-2017-006: Remote Code Execution in extension "PHPMailer" (bb_phpmailer) [4]https://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2017-006/ TYPO3-EXT-SA-2017-007: SQL Injection in extension "Content Rating Extbase" (content_rating_extbase) [5]https://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2017-007/ In general the TYPO3 Security Team recommends to read the following pages: The TYPO3 Security Guide: [6]https://docs.typo3.org/typo3cms/SecurityGuide/ Make sure you are subscribed to the TYPO3 Announce List: [7]http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce See all TYPO3 security advisories: [8]https://typo3.org/teams/security/security-bulletins/ Regards, Torben Hansen Member of the TYPO3 Security Team -- TYPO3 Security Team homepage: [9]https://typo3.org/teams/security/ E-Mail: security@typo3.org Please note: When replying to this e-mail, please leave the header intact. [1] https://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2017-003/ [2] https://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2017-004/ [3] https://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2017-005/ [4] https://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2017-006/ [5] https://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2017-007/ [6] https://docs.typo3.org/typo3cms/SecurityGuide/ [7] http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce [8] https://typo3.org/teams/security/security-bulletins/ [9] https://typo3.org/teams/security/