Fabian Mihailowitsch has reported a vulnerability in Contao, which can be exploited by malicious users to conduct SQL injection attacks.
Input passed via the "field" parameter to system/modules/backend/Ajax.php is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries and overwrite certain fields in the database.
The vulnerability is reported in version 2.11.3. Prior versions may also be affected.