SQL Injection Vulnerability in TYPO3's Forms Export Module
CVE-2026-77137
7.7HIGH
What is CVE-2026-77137?
The TYPO3 Forms Export module is vulnerable due to inadequate sanitization of user input, enabling low-privileged backend users to conduct SQL injection attacks via a URL parameter. This security flaw permits attackers to manipulate database queries if they possess read access to the Forms Export backend module. Proper input validation measures are essential to mitigate such vulnerabilities and protect the integrity of the database.
Affected Version(s)
Extension "Forms Export" 7.0.0 < 7.1.1
Extension "Forms Export" 6.0.0 < 6.1.3
Extension "Forms Export" 0 < 5.0.5
