HIGH
GHSA-9895-53fc-98v2
TYPO3 SQL Injection in dbal
Quick fix
GHSA-9895-53fc-98v2 — typo3/cms: upgrade to the fixed version with the command below.
composer require typo3/cms:^6.2.18Details
A flaw in the database escaping API results in a SQL injection vulnerability when extension dbal is enabled and configured for MySQL passthrough mode in its extension configuration. All queries which use the DatabaseConnection::sql_query are vulnerable, even if arguments were properly escaped with DatabaseConnection::quoteStr beforehand.
Are you affected?
Enter the version of the package you're using.