Description
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the admin search find API has a SQL injection vulnerability. Users should upgrade to version 10.5.21 to receive a patch or, as a workaround, apply the patch manually.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1216 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the admin search find API has a SQL injection vulnerability. Users should upgrade to version 10.5.21 to receive a patch or, as a workaround, apply the patch manually. |
Github GHSA |
GHSA-6mhm-gcpf-5gr8 | SQL Injection in Admin Search Find API |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-30T19:35:53.770Z
Reserved: 2023-04-18T16:13:15.881Z
Link: CVE-2023-30848
No data.
Status : Modified
Published: 2023-04-27T16:15:11.273
Modified: 2024-11-21T08:00:57.933
Link: CVE-2023-30848
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA