Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g868-j3qm-4j28

Опубликовано: 19 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.2

Описание

georgringer/news has SQL Injection in extension "News system" (news)

The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the TypoScript/Plugin setting disableOverrideDemand not to be enabled.

Пакеты

Наименование

georgringer/news

composer
Затронутые версииВерсия исправления

>= 12.0.0, < 12.3.2

12.3.2

Наименование

georgringer/news

composer
Затронутые версииВерсия исправления

>= 13.0.0, < 13.0.2

13.0.2

Наименование

georgringer/news

composer
Затронутые версииВерсия исправления

>= 14.0.0, < 14.0.3

14.0.3

Наименование

georgringer/news

composer
Затронутые версииВерсия исправления

< 10.0.4

10.0.4

Наименование

georgringer/news

composer
Затронутые версииВерсия исправления

>= 11.0.0, < 11.4.4

11.4.4

EPSS

Процентиль: 31%
0.00386
Низкий

8.2 High

CVSS4

Дефекты

CWE-89

Связанные уязвимости

nvd
3 месяца назад

The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the TypoScript/Plugin setting disableOverrideDemand not to be enabled.

EPSS

Процентиль: 31%
0.00386
Низкий

8.2 High

CVSS4

Дефекты

CWE-89