SQL Injection Vulnerability in TYPO3 Dynamic Content Element Extension
CVE-2021-31777
4.9MEDIUM
Key Information:
- Status
- Vendor
- CVE Published:
- 28 April 2021
What is CVE-2021-31777?
The Dynamic Content Element extension for TYPO3 provides an attack vector through SQL injection when a backend user account is compromised. Versions 2.2.0 up to 2.6.x prior to 2.6.2, and 2.7.x before 2.7.1 are affected, allowing unauthorized SQL queries to be executed by malicious users. This vulnerability underscores the necessity for prompt updates and security measures to protect data integrity within TYPO3 installations.
