TYPO3 before 8.7.30 Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) Vulnerability
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vulnerable to SQL injection.
The information has been provided by Dhiraj Shrikant Datar
The original article can be found at:https://review.typo3.org/q/%2522Resolves:+%252389452%2522+topic:security
Exploitation requires having the system extension ext:lowlevel installed, and a valid backend user who has administrator privileges.
TYPO3 before 8.7.30
TYPO3 9.x before 9.5.12
TYPO3 10.x before 10.2.2.