Skip to content

Possible SQL injection in widget field value

High
aschempp published GHSA-v3mr-gp7j-pw5w Feb 4, 2022

Package

composer terminal42/contao-tablelookupwizard (Composer)

Affected versions

< 3.3.5

Patched versions

3.3.5, 4.0.0

Description

Impact

The currently selected widget values were not correctly sanitized before passing it to the database, leading to an SQL injection possibility.

Patches

The issue has been patched in tablelookupwizard version 3.3.5 and version 4.0.0.

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs