Skip to main navigation Skip to main content Skip to page footer

Vulnerabilities in multiple third party TYPO3 CMS extensions

15 June 2015 ยท TYPO3 Security Team
Dear TYPO3 users,


several vulnerabilities have been found in the following third party TYPO3 extensions:

Frontend User Upload (feupload)
BE User Log (beko_beuserlog)
wt_directory (wt_directory)
Store Locator (locator)
Smoelenboek (ncgov_smoelenboek)
Developer Log (devlog)
FAQ - Frequently Asked Questions (js_faq)

For further information on the issues, please read the related advisories TYPO3-EXT-SA-2015-006, TYPO3-EXT-SA-2015-007, TYPO3-EXT-SA-2015-008, TYPO3-EXT-SA-2015-009, TYPO3-EXT-SA-2015-010, TYPO3-EXT-SA-2015-011, TYPO3-EXT-SA-2015-012 which were published today:

http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2015-006/
http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2015-007/
http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2015-008/
http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2015-009/
http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2015-010/
http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2015-011/
http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2015-012/


In general the TYPO3 Security Team recommends to read the following pages:

The TYPO3 Security Guide:
http://docs.typo3.org/typo3cms/SecurityGuide/

Make sure you are subscribed to the TYPO3 Announce List:
http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce

See all TYPO3 security advisories:
http://typo3.org/teams/security/security-bulletins/


Regards,

Helmut Hummel
Member of the TYPO3 Security Team

--
TYPO3 Security Team homepage: http://typo3.org/teams/security/

E-Mail: security@typo3.org