GHSA-rg6g-v4xm-g49q

Suggest an improvement
Source
https://github.com/advisories/GHSA-rg6g-v4xm-g49q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rg6g-v4xm-g49q/GHSA-rg6g-v4xm-g49q.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rg6g-v4xm-g49q
Aliases
  • CVE-2013-4748
Published
2022-05-17T01:33:01Z
Modified
2025-04-12T04:12:08.469754Z
Severity
  • 8.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
News system (news) extension for TYPO3 vulnerable to SQL Injection
Details

SQL injection vulnerability in the News system (news) extension before 1.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Database specific
{
    "github_reviewed": true,
    "nvd_published_at": "2013-07-01T23:55:00Z",
    "severity": "HIGH",
    "github_reviewed_at": "2025-04-12T03:13:23Z",
    "cwe_ids": [
        "CWE-89"
    ]
}
References

Affected packages

Packagist / georgringer/news

Package

Name
georgringer/news
Purl
pkg:composer/georgringer/news

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rg6g-v4xm-g49q/GHSA-rg6g-v4xm-g49q.json"