![](/assets/img/cve_300x82_sin_bg.png)
CVE-2019-19850
https://notcve.org/view.php?id=CVE-2019-19850
17 Dec 2019 — An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vulnerable to SQL injection. Exploitation requires having the system extension ext:lowlevel installed, and a valid backend user who has administrator privileges. Se descubrió un problema en TYPO3 versiones anteriores a la versión 8.7.30, versiones 9.x anteriores a la versión 9.5.12 y versiones 10.x anteriores a la versión 10.2.2. Deb... • https://review.typo3.org/q/%2522Resolves:+%252389452%2522+topic:security • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2019-19848
https://notcve.org/view.php?id=CVE-2019-19848
17 Dec 2019 — An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privileges are required in order to exploit this vulnerability. (In v9 LTS and later, System Maintainer privileges are also required.) Se descubrió un problema en TYPO3 versiones anteriores a la versión 8.7.30, versiones 9.x anteriores a la versión 9.5.12 y versiones 10.x anteri... • https://review.typo3.org/q/%2522Resolves:+%252388764%2522+topic:security • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •