CRITICAL9.8
GHSA-v3mr-gp7j-pw5w
Possible SQL injection in tablelookupwizard Contao Extension
Quick fix
GHSA-v3mr-gp7j-pw5w — terminal42/contao-tablelookupwizard: upgrade to the fixed version with the command below.
composer require terminal42/contao-tablelookupwizard:^3.3.5Details
### Impact The currently selected widget values were not correctly sanitized before passing it to the database, leading to an SQL injection possibility.
### Patches The issue has been patched in `tablelookupwizard` version 3.3.5 and version 4.0.0.
### For more information If you have any questions or comments about this advisory: * Open an issue in https://github.com/terminal42/contao-tablelookupwizard * Email us at [info@terminal42.ch](mailto:info@terminal42.ch)
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/terminal42/contao-tablelookupwizard
Introduced in:
0Fixed in: 3.3.5Fix
composer require terminal42/contao-tablelookupwizard:^3.3.5References
- https://github.com/terminal42/contao-tablelookupwizard/security/advisories/GHSA-v3mr-gp7j-pw5w[WEB]
- https://github.com/terminal42/contao-tablelookupwizard/commit/a5e723a28f110b7df8ffc4175cef9b061d3cc717[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/terminal42/contao-tablelookupwizard/2022-02-04-1.yaml[WEB]
- https://github.com/terminal42/contao-tablelookupwizard[PACKAGE]