friendsoftypo3/tt-address
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*
- 10.0.0
- 9.0.0 - 9.1.0
- <= 8.1.1
A SQL injection vulnerability has been identified in the 'Address List' (tt_address) extension for TYPO3. The issue arises in the AddressRepository::getSqlQuery() method, which constructs database queries without adequately sanitizing user input. While this vulnerability is not exploited in the default installation of the extension, it could be introduced by custom extensions that call this method with untrusted input.
Exploitation of this vulnerability allows for SQL injection, where an attacker can manipulate database queries. This could lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations on the database.
Users of the 'Address List' extension are advised to update to version 10.0.1, 9.1.1, or 8.1.2. These versions are available through the TYPO3 Extension Manager, Packagist, and the TYPO3 Extensions Repository.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.