Description
A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6412 | A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3. |
Github GHSA |
GHSA-rpxg-hg79-h8q9 | SQL Injection in typo3 extension "LUX - TYPO3 Marketing Automation" |
References
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2022-014 |
|
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T09:36:44.409Z
Reserved: 2022-07-11T00:00:00.000Z
Link: CVE-2022-35628
No data.
Status : Modified
Published: 2022-07-12T23:15:14.093
Modified: 2026-06-17T04:52:00.007
Link: CVE-2022-35628
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
EUVD
Github GHSA