Executive brief
The TYPO3 Address List (tt_address) extension contains a security flaw that could allow unauthorized access to database information. While the vulnerable component is not used by the extension itself in a standard setup, it poses a risk if other custom website features utilize this specific component. If exploited, an attacker could potentially view sensitive data stored in the website's database.
Technical details
An SQL injection vulnerability exists in the TYPO3 extension 'tt_address' (Address List) within the AddressRepository::getSqlQuery() method. The root cause is the construction of database queries using unsanitized user input. While the method is not called by the extension's default code, it is accessible to third-party extensions or custom code. A remote attacker could exploit this via network requests if a custom implementation passes untrusted input to this method, potentially leading to unauthorized data exfiltration. The issue is resolved in versions 8.1.2, 9.1.1, and 10.0.1.
Affected products
- TYPO3 tt_address < 8.1.2, >= 9.0.0 < 9.1.1, >= 10.0.0 < 10.0.1
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory
- 2026-06-29: other: Advisory updated
References
- https://api.github.com/users/eliashaeussler
- https://github.com/eliashaeussler
- https://api.github.com/users/eliashaeussler/gists%7B/gist_id%7D
- https://api.github.com/users/eliashaeussler/repos
- https://avatars.githubusercontent.com/u/16313625?v=4
- https://api.github.com/users/eliashaeussler/events%7B/privacy%7D