Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-8827

3 месяца назад

The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading to SQL Injection. The method is not invoked anywhere within the extension itself and therefore poses no direct risk in a default installation. However, custom extensions that call this method with untrusted input would expose the site to SQL injection.

EPSS: Низкий
github логотип

GHSA-3h52-6v6j-6wwv

3 месяца назад

TYPO3 SQL Injection in extension "Address List" (tt_address)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-8827

The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading to SQL Injection. The method is not invoked anywhere within the extension itself and therefore poses no direct risk in a default installation. However, custom extensions that call this method with untrusted input would expose the site to SQL injection.

0%
Низкий
3 месяца назад
github логотип
GHSA-3h52-6v6j-6wwv

TYPO3 SQL Injection in extension "Address List" (tt_address)

0%
Низкий
3 месяца назад

Уязвимостей на страницу