Impact
The vulnerability lies in the "Forms Export" extension’s failure to sanitize user input that is later incorporated into a database query. A user with low-level backend privileges can craft a URL parameter and inject arbitrary SQL statements through the backend module’s interface, allowing unauthorized read or modification of the database contents. This flaw directly compromises the confidentiality and integrity of stored data.
Affected Systems
TYPO3 CMS installations that have the Forms Export extension (frp_form_answers) enabled are affected. The specific extension versions are not identified in the advisories, so any version containing the improper input handling is at risk. The flaw can be triggered by any backend user with read access to the Forms Export module, regardless of broader system permissions.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a low-privileged backend user with read access to the module, meaning that internal users or compromised credentials can readily exploit the flaw without additional network-level access or privilege escalation.
OpenCVE Enrichment