Possible SQL injection in tablelookupwizard Contao Extension
High severity
GitHub Reviewed
Published
Feb 4, 2022
in
terminal42/contao-tablelookupwizard
•
Updated Jan 11, 2023
Package
Affected versions
< 3.3.5
Patched versions
3.3.5
Description
Reviewed
Feb 4, 2022
Published to the GitHub Advisory Database
Feb 10, 2022
Last updated
Jan 11, 2023
Impact
The currently selected widget values were not correctly sanitized before passing it to the database, leading to an SQL injection possibility.
Patches
The issue has been patched in
tablelookupwizard
version 3.3.5 and version 4.0.0.For more information
If you have any questions or comments about this advisory:
References