An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vulnerable to SQL injection. Exploitation requires having the system extension ext:lowlevel installed, and a valid backend user who has administrator privileges.
2019-12-17T17:15:18.067
2024-11-21T04:35:31.710
Modified
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | typo3 | typo3 | < 8.7.30 | Yes |
Application | typo3 | typo3 | < 9.5.12 | Yes |
Application | typo3 | typo3 | < 10.2.2 | Yes |