GHSA-9568-hcj9-rf7v

Suggest an improvement
Source
https://github.com/advisories/GHSA-9568-hcj9-rf7v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9568-hcj9-rf7v/GHSA-9568-hcj9-rf7v.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-9568-hcj9-rf7v
Aliases
  • CVE-2010-4961
Published
2022-05-17T01:56:34Z
Modified
2025-04-12T02:27:12.336659Z
Severity
  • 8.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
Webkit PDFs for TYPO3 has SQL Injection vulnerability
Details

SQL injection vulnerability in the Webkit PDFs (webkitpdf) extension before 1.1.4 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Database specific
{
    "nvd_published_at": "2011-10-09T10:55:00Z",
    "cwe_ids": [
        "CWE-89"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2025-04-12T02:01:45Z"
}
References

Affected packages

Packagist / dmk/webkitpdf

Package

Name
dmk/webkitpdf
Purl
pkg:composer/dmk/webkitpdf

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.4