{"id":"GHSA-v3mr-gp7j-pw5w","summary":"Possible SQL injection in tablelookupwizard Contao Extension","details":"### Impact\nThe currently selected widget values were not correctly sanitized before passing it to the database, leading to an SQL injection possibility.\n\n### Patches\nThe issue has been patched in `tablelookupwizard` version 3.3.5 and version 4.0.0.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in https://github.com/terminal42/contao-tablelookupwizard\n* Email us at [info@terminal42.ch](mailto:info@terminal42.ch)","modified":"2026-02-03T03:08:50.142272Z","published":"2022-02-10T22:33:46Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-89"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-02-04T17:26:40Z"},"references":[{"type":"WEB","url":"https://github.com/terminal42/contao-tablelookupwizard/security/advisories/GHSA-v3mr-gp7j-pw5w"},{"type":"WEB","url":"https://github.com/terminal42/contao-tablelookupwizard/commit/a5e723a28f110b7df8ffc4175cef9b061d3cc717"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/terminal42/contao-tablelookupwizard/2022-02-04-1.yaml"},{"type":"PACKAGE","url":"https://github.com/terminal42/contao-tablelookupwizard"}],"affected":[{"package":{"name":"terminal42/contao-tablelookupwizard","ecosystem":"Packagist","purl":"pkg:composer/terminal42/contao-tablelookupwizard"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.5"}]}],"versions":["2.0.1","3.0.0","3.1.0","3.1.1","3.1.2","3.1.3","3.2.0","3.2.1","3.3.0","3.3.1","3.3.2","3.3.3","3.3.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-v3mr-gp7j-pw5w/GHSA-v3mr-gp7j-pw5w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}