PT-2019-12035 · Pimcore · Pimcore
Published
2019-11-18
·
Updated
2020-03-18
·
CVE-2019-10763
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
pimcore/pimcore versions prior to 6.3.0
Description
The issue allows an attacker with limited privileges, specifically classes permission, to achieve SQL injection, potentially leading to data leakage. This can be exploited through the
id, storeId, pageSize, and tables parameters by using a payload to trigger time-based or error-based SQL injection.Recommendations
For versions prior to 6.3.0, update to version 6.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the parameters
id, storeId, pageSize, and tables to minimize the risk of exploitation.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pimcore