Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v3mr-gp7j-pw5w

Опубликовано: 10 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Possible SQL injection in tablelookupwizard Contao Extension

Impact

The currently selected widget values were not correctly sanitized before passing it to the database, leading to an SQL injection possibility.

Patches

The issue has been patched in tablelookupwizard version 3.3.5 and version 4.0.0.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

terminal42/contao-tablelookupwizard

composer
Затронутые версииВерсия исправления

< 3.3.5

3.3.5

9.8 Critical

CVSS3

Дефекты

CWE-89

9.8 Critical

CVSS3

Дефекты

CWE-89