{"id":"GHSA-v3mr-gp7j-pw5w","aliases":[],"url":"https://o3.security/vulnerability/GHSA-v3mr-gp7j-pw5w","summary":"Possible SQL injection in tablelookupwizard Contao Extension","details":"### Impact\nThe currently selected widget values were not correctly sanitized before passing it to the database, leading to an SQL injection possibility.\n\n### Patches\nThe issue has been patched in `tablelookupwizard` version 3.3.5 and version 4.0.0.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in https://github.com/terminal42/contao-tablelookupwizard\n* Email us at [info@terminal42.ch](mailto:info@terminal42.ch)","published":"2022-02-10T22:33:46Z","modified":"2026-02-03T03:08:50.142272Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"terminal42/contao-tablelookupwizard","fixedVersion":"3.3.5"}],"fix":{"url":"https://github.com/terminal42/contao-tablelookupwizard/commit/a5e723a28f110b7df8ffc4175cef9b061d3cc717","label":"terminal42/contao-tablelookupwizard@a5e723a"},"references":[{"type":"WEB","url":"https://github.com/terminal42/contao-tablelookupwizard/security/advisories/GHSA-v3mr-gp7j-pw5w"},{"type":"WEB","url":"https://github.com/terminal42/contao-tablelookupwizard/commit/a5e723a28f110b7df8ffc4175cef9b061d3cc717"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/terminal42/contao-tablelookupwizard/2022-02-04-1.yaml"},{"type":"PACKAGE","url":"https://github.com/terminal42/contao-tablelookupwizard"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-03T03:08:50.142272Z"}}