Description
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vulnerable to SQL injection. Exploitation requires having the system extension ext:lowlevel installed, and a valid backend user who has administrator privileges.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-2442 Vulnerability (CVE-2013-2442)
TYPO3 URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2010-3661)
WordPress Plugin eventON Multiple Cross-Site Scripting Vulnerabilities (2.6.11)
WordPress 6.2.x Multiple Vulnerabilities (6.2 - 6.2.2)
Oracle Application Server CVE-2006-3707 Vulnerability (CVE-2006-3707)