PT-2026-70137 · Pimcore · Admin Classic Bundle
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pimcore admin-ui-classic-bundle versions prior to 2.4
Description
An SQL injection issue exists where authenticated backend users can execute arbitrary SQL commands. This occurs because the filter value in the DataObject grid
id column filter is concatenated directly into the SQL WHERE clause without parameterization. An attacker with backend access can use this to exfiltrate or modify all database contents.Recommendations
Update Pimcore admin-ui-classic-bundle to version 2.4 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Admin Classic Bundle