Pimcore Admin Classic Bundle是Pimcore公司的一款经典后台管理界面组件集合。 Pimcore Admin Classic Bundle 2.3及之前版本存在SQL注入漏洞,该漏洞源于DataObject grid id column filter过滤值未参数化直接拼接到SQL WHERE子句,可能导致经过身份验证的后端用户执行任意SQL,从而泄露或修改所有数据库内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Pimcore | pimcore admin-ui-classic-bundle | ≤ 2.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Pimcore | pimcore admin-ui-classic-bundle | 0 ~ 2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet