296,747
Total vulnerabilities in the database
A flaw in the database escaping API results in a SQL injection vulnerability when extension dbal is enabled and configured for MySQL passthrough mode in its extension configuration. All queries which use the DatabaseConnection::sql_query are vulnerable, even if arguments were properly escaped with DatabaseConnection::quoteStr beforehand.
| Software | From | Fixed in |
|---|---|---|
typo3 / cms
|
6.2.0 | 6.2.18 |