PT-2026-41868 · Unknown · Address List
Georg Ringer
·
Published
2026-05-19
·
Updated
2026-05-19
·
CVE-2026-8827
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Address List (tt address) (affected versions not specified)
Description
The
AddressRepository::getSqlQuery() function constructs a database query without properly sanitizing user input, which can lead to SQL Injection (a technique where malicious SQL statements are inserted into entry fields for execution). While this method is not called within the extension by default, custom extensions that invoke it using untrusted input can expose the site to this risk.Recommendations
As a temporary workaround, avoid calling the
getSqlQuery() function with untrusted input in custom extensions.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Address List