Description
pimcore/pimcore before 6.3.0 is vulnerable to SQL Injection. An attacker with limited privileges (classes permission) can achieve a SQL injection that can lead in data leakage. The vulnerability can be exploited via 'id', 'storeId', 'pageSize' and 'tables' parameters, using a payload for trigger a time based or error based sql injection.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0790 | pimcore/pimcore before 6.3.0 is vulnerable to SQL Injection. An attacker with limited privileges (classes permission) can achieve a SQL injection that can lead in data leakage. The vulnerability can be exploited via 'id', 'storeId', 'pageSize' and 'tables' parameters, using a payload for trigger a time based or error based sql injection. |
Github GHSA |
GHSA-fpff-384j-vxq7 | Data leakage via SQL Injection in Pimcore |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-08-04T22:32:01.595Z
Reserved: 2019-04-03T00:00:00.000Z
Link: CVE-2019-10763
No data.
Status : Modified
Published: 2019-11-18T20:15:11.067
Modified: 2024-11-21T04:19:52.480
Link: CVE-2019-10763
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA