PT-2019-12035 · Pimcore · Pimcore

Published

2019-11-18

·

Updated

2020-03-18

·

CVE-2019-10763

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions pimcore/pimcore versions prior to 6.3.0
Description The issue allows an attacker with limited privileges, specifically classes permission, to achieve SQL injection, potentially leading to data leakage. This can be exploited through the id, storeId, pageSize, and tables parameters by using a payload to trigger time-based or error-based SQL injection.
Recommendations For versions prior to 6.3.0, update to version 6.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the parameters id, storeId, pageSize, and tables to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10763
GHSA-FPFF-384J-VXQ7
SNYK-PHP-PIMCOREPIMCORE-480391

Affected Products

Pimcore