Executive brief
The "News system" extension for TYPO3, which is used to manage and display news articles on websites, contains a security vulnerability. An attacker can use a specially crafted web link to access or manipulate database information without needing a password. This could lead to the exposure of sensitive site data or customer information.
Technical details
A SQL injection vulnerability exists in the georgringer/news (News system) extension for TYPO3. The root cause is a failure to properly sanitize user-supplied input before it is used in database queries within the "Date Menu of news articles" plugin. An unauthenticated attacker can trigger this via a malicious URL parameter. Exploitation is contingent upon the "Date Menu" plugin being active and the TypoScript 'disableOverrideDemand' setting not being enabled. Successful exploitation allows for unauthorized data retrieval from the database. Patches are available in versions 10.0.4, 11.4.4, 12.3.2, 13.0.2, and 14.0.3.
Affected products
- georgringer news < 10.0.4, >= 11.0.0 < 11.4.4, >= 12.0.0 < 12.3.2, >= 13.0.0 < 13.0.2, >= 14.0.0 < 14.0.3
Timeline
- 2026-05-19: advisory: Initial disclosure and NVD publication
- 2026-06-08: other: GitHub Advisory updated with CVSS 4.0 score
References
- https://api.github.com/users/eliashaeussler
- https://github.com/eliashaeussler
- https://api.github.com/users/eliashaeussler/gists%7B/gist_id%7D
- https://api.github.com/users/eliashaeussler/repos
- https://avatars.githubusercontent.com/u/16313625?v=4
- https://api.github.com/users/eliashaeussler/events%7B/privacy%7D