⚠ Withdrawn by GitHub Security Advisories
Withdrawn: May 28, 2026
GHSA-c8g3-x47w-8q7pHighDisclosed before NVD
Duplicate Advisory: Pimcore admin users can trigger SQL Injection
📋 Description
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-r2f4-ff2p-xc64. This link is maintained to preserve external references.
Original Description
An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend.
This issue affects pimcore: 12.3.3.
🎯 Affected products1
- composer/pimcore/pimcore:= 12.3.3