PT-2023-21204 · Pimcore · Pimcore/Customer-Data-Framework

Published

2023-05-17

·

Updated

2023-05-25

·

CVE-2023-2756

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pimcore/customer-data-framework versions prior to 3.3.10
Description The issue allows an administrator user to execute blind SQL queries using the inheritable segments feature. This can lead to the retrieval of sensitive data, modification of database information, or other malicious activities against the database.
Recommendations For versions prior to 3.3.10, update to version 3.3.10 to resolve the issue. As a temporary workaround, apply the patch manually from https://github.com/pimcore/customer-data-framework/commit/76df151737b7964ce5169fdf9e27a0ad801757fe.patch to mitigate the risk.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-2756
GHSA-25FX-3C2Q-CQ46

Affected Products

Pimcore/Customer-Data-Framework