It has been discovered that the extension fechangepassword is open for a SQL injection when updating the password.
It has been discovered that the extension ftpbrowser is doing incorrect authentication in some files, making it open for exploiting.
Multiple vulnerabilities have been found in the third party extension "mysqldumper". Full read/write access to the connected database and other related issues.
Due to an unplanned power failure at our network carrier, the data center where some typo3.org subdomains are hosted have been completely offline from June 24 04:37:15 UTC+2 to June 24 19:28:48 UTC+2
Affected services have...
It has been discovered that the extension w4x_backup has several security related issues, which may disclosure confidential information.
It has been discovered that the extensions macina_banners and its descendant ric_rotation are exposed to an SQL injection issue because they fail to properly sanitize user-supplied input.
The TYPO3 Core Team announces versions 4.1.1 and 4.0.6 of the TYPO3 Enterprise Content Management System.