VYPR

Packagist (Composer) package

t3/dce

pkg:composer/t3/dce

Vulnerabilities (2)

  • CVE-2021-31777MedApr 28, 2021
    affected >= 2.2.0, < 2.6.2fixed 2.6.2

    The dce (aka Dynamic Content Element) extension 2.2.0 through 2.6.x before 2.6.2, and 2.7.x before 2.7.1, for TYPO3 allows SQL Injection via a backend user account.

  • CVE-2014-8328MedFeb 3, 2020
    affected < 0.11.5fixed 0.11.5

    The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attackers to obtain sensitive installation environment information by reading the update check request.