Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-027 |
|
Tue, 25 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged backend user can inject arbitrary SQL through a URL parameter within the "Forms Export" backend module. Exploitation requires a low-privileged backend user and read access to the "Forms Export" Backend module. | |
| Title | SQL Injection in extension "Forms Export" (frp_form_answers) | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-08-25T09:00:38.789Z
Reserved: 2026-08-20T13:10:15.961Z
Link: CVE-2026-77137
No data.
Status : Received
Published: 2026-08-25T09:17:34.343
Modified: 2026-08-25T09:17:34.343
Link: CVE-2026-77137
No data.
OpenCVE Enrichment
Updated: 2026-08-25T10:45:03Z