Data leakage via SQL Injection in Pimcore
Moderate severity
GitHub Reviewed
Published
Dec 2, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Nov 27, 2019
Published to the GitHub Advisory Database
Dec 2, 2019
Last updated
Jan 9, 2023
pimcore/pimcore before 6.3.0 is vulnerable to SQL Injection. An attacker with limited privileges (classes permission) can achieve a SQL injection that can lead in data leakage. The vulnerability can be exploited via 'id', 'storeId', 'pageSize' and 'tables' parameters, using a payload for trigger a time based or error based sql injection.
References