Critical severity9.8NVD Advisory· Published Jul 12, 2022· Updated Jun 17, 2026
CVE-2022-35628
CVE-2022-35628
Description
A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
in2code/luxPackagist | >= 18.0.0, < 24.0.2 | 24.0.2 |
in2code/luxPackagist | < 17.6.1 | 17.6.1 |
Affected products
2- TYPO3/luxdescription
Patches
Vulnerability mechanics
References
4- typo3.org/security/advisory/typo3-ext-sa-2022-014nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-rpxg-hg79-h8q9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-35628ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/in2code/lux/CVE-2022-35628.yamlghsaWEB
News mentions
0No linked articles in our index yet.