TYPO3-EXT-SA-2025-012: Cross-Site Scripting in extension "Form to Database" (form_to_database)

Categories: Development Created by Torben Hansen
It has been discovered that the extension "Form to Database" (form_to_database) is susceptible to Cross-Site Scripting.

Problem Description

The extension fails to properly encode user input for output in HTML context in TYPO3 backend user interface.

Solution

Updated versions 2.2.5, 3.2.2, 4.2.3 and 5.0.2 are available from the TYPO3 extension manager, packagist and at
https://extensions.typo3.org/extension/download/form_to_database/2.2.5/zip  
https://extensions.typo3.org/extension/download/form_to_database/3.2.2/zip  
https://extensions.typo3.org/extension/download/form_to_database/4.2.3/zip  
https://extensions.typo3.org/extension/download/form_to_database/5.0.2/zip    

Users of the extension are advised to update the extension as soon as possible.

Credits

Thanks to Sascha Egerer for reporting the vulnerability and to Liquid Light for providing updated versions of the extension.

General Advice

Follow the recommendations that are given in the TYPO3 Security Guide. Please subscribe to the typo3-announce mailing list.