← back
CVE-2017-7581

CVE-2017-7581

30Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 48%
from disclosure to weapon0 days
Published on NVDApr 7
metasploitApr 6
exploitation probability
48%top 1% of all CVEs
observed exploitation
nono source reports it
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.
Affected products
n/a · n/a