An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column filter. The filter value is concatenated directly into the SQL WHERE clause without parameterization. An attacker with backend access can exfiltrate or modify all database contents.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/pimcore/admin-ui-classic-bundle |
|
History
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column filter. The filter value is concatenated directly into the SQL WHERE clause without parameterization. An attacker with backend access can exfiltrate or modify all database contents. | |
| Title | Pimcore pimcore admin-ui-classic-bundle - SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-11T12:17:54.337Z
Reserved: 2026-08-10T10:32:49.082Z
Link: CVE-2026-72562
No data.
No data.
No data.
OpenCVE Enrichment
No data.