⚠ Withdrawn by GitHub Security Advisories

Withdrawn: May 28, 2026

GHSA-c8g3-x47w-8q7pHighDisclosed before NVD

Duplicate Advisory: Pimcore admin users can trigger SQL Injection

Published
April 27, 2026
Last Modified
May 28, 2026

📋 Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-r2f4-ff2p-xc64. This link is maintained to preserve external references.

Original Description

An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend.

This issue affects pimcore: 12.3.3.

🎯 Affected products1

  • composer/pimcore/pimcore:= 12.3.3

🔗 References (5)