VDB
Sign up
HIGH

GHSA-9895-53fc-98v2

TYPO3 SQL Injection in dbal

Quick fix

GHSA-9895-53fc-98v2 — typo3/cms: upgrade to the fixed version with the command below.

composer require typo3/cms:^6.2.18

Details

A flaw in the database escaping API results in a SQL injection vulnerability when extension dbal is enabled and configured for MySQL passthrough mode in its extension configuration. All queries which use the DatabaseConnection::sql_query are vulnerable, even if arguments were properly escaped with DatabaseConnection::quoteStr beforehand.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/cms
Introduced in: 6.2.0Fixed in: 6.2.18
Fixcomposer require typo3/cms:^6.2.18

References