{"id":"CVE-2021-31777","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-31777","summary":"SQL Injection in t3/dce","details":"The dce (aka Dynamic Content Element) extension 2.2.0 through 2.6.x before 2.6.2, and 2.7.x before 2.7.1, for TYPO3 allows SQL Injection via a backend user account.","published":"2021-06-08T20:12:23Z","modified":"2024-02-17T05:35:17.294908Z","cvss":{"score":7.6,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L"},"epss":{"score":0.01406,"percentile":0.70133,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"t3/dce","fixedVersion":"2.6.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-31777"},{"type":"WEB","url":"https://bitbucket.org/ArminVieweg/dce/commits/998a2392f69f2153797c5ace6e8914ca309e70c7"},{"type":"WEB","url":"https://excellium-services.com/cert-xlm-advisory"},{"type":"WEB","url":"https://packagist.org/packages/t3/dce"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-ext-sa-2021-005"},{"type":"WEB","url":"http://packetstormsecurity.com/files/162429/TYPO3-6.2.1-SQL-Injection.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-02-17T05:35:17.294908Z"}}