CVE-2022-35628: SQL Injection
A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.
Other sources
TYPO3-EXT-SA-2022-014: SQL Injection in extension "LUX - TYPO3 Marketing Automation" (lux)
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35628?
CVE-2022-35628 is classified as a high severity SQL injection vulnerability that can lead to unauthorized access to the database.
How do I fix CVE-2022-35628?
To fix CVE-2022-35628, upgrade the 'lux' extension to version 17.6.1 or higher, or version 24.0.2 or higher.
Which versions are affected by CVE-2022-35628?
CVE-2022-35628 affects 'lux' extension versions prior to 17.6.1 and between 18.0.0 and 24.0.1.
What is the impact of CVE-2022-35628?
The impact of CVE-2022-35628 includes potential data leakage and unauthorized manipulation of the TYPO3 database.
Was CVE-2022-35628 publicly disclosed?
Yes, CVE-2022-35628 was publicly disclosed as part of TYPO3 security advisory TYPO3-EXT-SA-2022-014.