PT-2026-41868 · Unknown · Address List

Georg Ringer

·

Published

2026-05-19

·

Updated

2026-05-19

·

CVE-2026-8827

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Address List (tt address) (affected versions not specified)
Description The AddressRepository::getSqlQuery() function constructs a database query without properly sanitizing user input, which can lead to SQL Injection (a technique where malicious SQL statements are inserted into entry fields for execution). While this method is not called within the extension by default, custom extensions that invoke it using untrusted input can expose the site to this risk.
Recommendations As a temporary workaround, avoid calling the getSqlQuery() function with untrusted input in custom extensions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-8827

Affected Products

Address List