A weakness in the display of forum messages of chc_forum has been
discovered that may be used to execute arbitrary SQL
After more than one year of hard work I am glad to announce the launch of TER2, our new extension repository. But that's not all: At the same time an improved and redesigned version of TYPO3.org goes online.
Multiple TYPO3 Security Bulletins have been issued, all of which are addressed by the release of TYPO3 3.8.1.
Two security bulletins regarding the 3rd party extensions "CHC Forum" and "th_mailformplus" have been issued today. Fixed versions are available.
A bug has been discovered in the "Front End News Submitter" (fe_news) where SQL injection is not safely prevented. fe_rtenews is affected as well.
A bug has been discovered in MOC filemanager (v. 0.7.1 and earlier): An offender may gain illegal read access to files on the server.
Possible remote exploit with AWStats. The TYPO3 Security Team has issued a security bulletin which explains and fixes a possible problem with extensions shipping AWStats.