Medium severity4.9NVD Advisory· Published Apr 28, 2021· Updated Jun 17, 2026
CVE-2021-31777
CVE-2021-31777
Description
The dce (aka Dynamic Content Element) extension 2.2.0 through 2.6.x before 2.6.2, and 2.7.x before 2.7.1, for TYPO3 allows SQL Injection via a backend user account.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
t3/dcePackagist | >= 2.2.0, < 2.6.2 | 2.6.2 |
Affected products
2- cpe:2.3:a:dynamic_content_elements_project:dynamic_content_elements:*:*:*:*:*:typo3:*:*Range: >=2.2.0,<2.6.2
Patches
Vulnerability mechanics
References
9- typo3.org/security/advisory/typo3-ext-sa-2021-005nvdPatchThird Party AdvisoryWEB
- packetstormsecurity.com/files/162429/TYPO3-6.2.1-SQL-Injection.htmlnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-5v5h-4w2g-gxxcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-31777ghsaADVISORY
- bitbucket.org/ArminVieweg/dce/commits/998a2392f69f2153797c5ace6e8914ca309e70c7ghsaWEB
- excellium-services.com/cert-xlm-advisoryghsaWEB
- excellium-services.com/cert-xlm-advisory/nvdNot Applicable
- packagist.org/packages/t3/dceghsaWEB
- cds.thalesgroup.com/en/tcs-cert/CVE-2021-31777nvd
News mentions
0No linked articles in our index yet.