Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9895-53fc-98v2

Опубликовано: 03 июн. 2024
Источник: github
Github: Прошло ревью

Описание

TYPO3 SQL Injection in dbal

A flaw in the database escaping API results in a SQL injection vulnerability when extension dbal is enabled and configured for MySQL passthrough mode in its extension configuration. All queries which use the DatabaseConnection::sql_query are vulnerable, even if arguments were properly escaped with DatabaseConnection::quoteStr beforehand.

Пакеты

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 6.2.0, < 6.2.18

6.2.18