VDB
Sign up
CRITICAL9.8

GHSA-v3mr-gp7j-pw5w

Possible SQL injection in tablelookupwizard Contao Extension

Quick fix

GHSA-v3mr-gp7j-pw5w — terminal42/contao-tablelookupwizard: upgrade to the fixed version with the command below.

composer require terminal42/contao-tablelookupwizard:^3.3.5

Details

### Impact The currently selected widget values were not correctly sanitized before passing it to the database, leading to an SQL injection possibility.

### Patches The issue has been patched in `tablelookupwizard` version 3.3.5 and version 4.0.0.

### For more information If you have any questions or comments about this advisory: * Open an issue in https://github.com/terminal42/contao-tablelookupwizard * Email us at [info@terminal42.ch](mailto:info@terminal42.ch)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/terminal42/contao-tablelookupwizard
Introduced in: 0Fixed in: 3.3.5
Fixcomposer require terminal42/contao-tablelookupwizard:^3.3.5

References