This issue affects pimcore: 12.3.3.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c8g3-x47w-8q7p | Pimcore admin users can trigger SQL Injection |
Tue, 05 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 28 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. This issue affects pimcore: 12.3.3. | |
| Title | Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling | |
| First Time appeared |
Pimcore
Pimcore pimcore |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:pimcore:pimcore:12.3.3:*:linux:*:*:*:*:* cpe:2.3:a:pimcore:pimcore:12.3.3:*:macos:*:*:*:*:* cpe:2.3:a:pimcore:pimcore:12.3.3:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Pimcore
Pimcore pimcore |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-05-05T17:17:45.826Z
Reserved: 2026-04-01T23:34:42.722Z
Link: CVE-2026-5394
Updated: 2026-04-28T13:21:13.334Z
Status : Deferred
Published: 2026-04-27T20:16:28.450
Modified: 2026-05-05T18:16:03.470
Link: CVE-2026-5394
No data.
OpenCVE Enrichment
Updated: 2026-04-28T13:00:15Z
Github GHSA