The currently selected widget values were not correctly sanitized before passing it to the database, leading to an SQL injection possibility.
The issue has been patched in tablelookupwizard
version 3.3.5 and version 4.0.0.
If you have any questions or comments about this advisory: * Open an issue in https://github.com/terminal42/contao-tablelookupwizard * Email us at info@terminal42.ch
{ "nvd_published_at": null, "cwe_ids": [ "CWE-89" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-02-04T17:26:40Z" }