Skip to main navigation Skip to main content Skip to page footer

Vulnerabilities in one third party TYPO3 CMS extension

24 March 2016 ยท Nicole Cordes
Dear TYPO3 users,

several vulnerabilities have been found in the following third party TYPO3 extension:

"Ajax mail subscription" (ods_ajaxmailsubscription)
 
For further information on the issue, please read the related advisory TYPO3-EXT-SA-2016-009 which was published today:

TYPO3-EXT-SA-2016-009: Multiple vulnerabilities in extension "Ajax mail subscription" (ods_ajaxmailsubscription)
https://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2016-009/


In general the TYPO3 Security Team recommends to read the following pages:

The TYPO3 Security Guide:
https://docs.typo3.org/typo3cms/SecurityGuide/

Make sure you are subscribed to the TYPO3 Announce List:
http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce

See all TYPO3 security advisories:
https://typo3.org/teams/security/security-bulletins/


Regards,

Nicole Cordes
Member of the TYPO3 Security Team

--
TYPO3 Security Team homepage: https://typo3.org/teams/security/

E-Mail: security@typo3.org