Vulnerability Description
pimcore/pimcore before 6.3.0 is vulnerable to SQL Injection. An attacker with limited privileges (classes permission) can achieve a SQL injection that can lead in data leakage. The vulnerability can be exploited via 'id', 'storeId', 'pageSize' and 'tables' parameters, using a payload for trigger a time based or error based sql injection.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pimcore | Pimcore | < 6.3.0 |
Related Weaknesses (CWE)
References
- https://blog.certimetergroup.com/it/articolo/security/sql_injection_in_pimcore_6
- https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-480391Third Party Advisory
- https://blog.certimetergroup.com/it/articolo/security/sql_injection_in_pimcore_6
- https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-480391Third Party Advisory
FAQ
What is CVE-2019-10763?
CVE-2019-10763 is a vulnerability with a CVSS score of 6.5 (MEDIUM). pimcore/pimcore before 6.3.0 is vulnerable to SQL Injection. An attacker with limited privileges (classes permission) can achieve a SQL injection that can lead in data leakage. The vulnerability can b...
How severe is CVE-2019-10763?
CVE-2019-10763 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10763?
Check the references section above for vendor advisories and patch information. Affected products include: Pimcore Pimcore.