The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the TypoScript/Plugin setting disableOverrideDemand not to be enabled.
Update georgringer/news to 12.3.2; georgringer/news to 13.0.2; georgringer/news to 14.0.3; georgringer/news to 10.0.4; georgringer/news to 11.4.4 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scangeorgringer/news has SQL Injection in extension "News system" (news) affects georgringer/news (composer), georgringer/news (composer), georgringer/news (composer), georgringer/news (composer), georgringer/news (composer). Severity is high. The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the TypoScript/Plugin setting disableOverrideDemand not to be enabled.
AI coding agents often install or upgrade packages automatically in composer. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| georgringer/news |
The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the TypoScript/Plugin setting disableOverrideDemand not to be enabled.
Update georgringer/news to 12.3.2; georgringer/news to 13.0.2; georgringer/news to 14.0.3; georgringer/news to 10.0.4; georgringer/news to 11.4.4 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scangeorgringer/news has SQL Injection in extension "News system" (news) affects georgringer/news (composer), georgringer/news (composer), georgringer/news (composer), georgringer/news (composer), georgringer/news (composer). Severity is high. The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the TypoScript/Plugin setting disableOverrideDemand not to be enabled.
AI coding agents often install or upgrade packages automatically in composer. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| georgringer/news |
| >=12.0.0,<12.3.2 |
| 12.3.2 |
| georgringer/newscomposer | >=13.0.0,<13.0.2 | 13.0.2 |
|---|
| georgringer/newscomposer | >=14.0.0,<14.0.3 | 14.0.3 |
|---|
| georgringer/newscomposer | <10.0.4 | 10.0.4 |
|---|
| georgringer/newscomposer | >=11.0.0,<11.4.4 | 11.4.4 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=12.0.0,<12.3.2 |
| 12.3.2 |
| georgringer/newscomposer | >=13.0.0,<13.0.2 | 13.0.2 |
|---|
| georgringer/newscomposer | >=14.0.0,<14.0.3 | 14.0.3 |
|---|
| georgringer/newscomposer | <10.0.4 | 10.0.4 |
|---|
| georgringer/newscomposer | >=11.0.0,<11.4.4 | 11.4.4 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard