CVE-2026-77137

Summary

The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged backend user can inject arbitrary SQL through a URL parameter within the "Forms Export" backend module. Exploitation requires a low-privileged backend user and read access to the "Forms Export" Backend module.

Affected Software

VendorProductVersion RangeStatus
TYPO3Extension “Forms Export”7.0.0 < 7.1.1affected
TYPO3Extension “Forms Export”6.0.0 < 6.1.3affected
TYPO3Extension “Forms Export”0 < 5.0.5affected

Weaknesses

  • CWE-89: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References