An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend.
This issue affects pimcore: 12.3.3.
CVSS
No CVSS.
References
Configurations
No configuration.
History
05 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
27 Apr 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-27 20:16
Updated : 2026-06-17 10:58
NVD link : CVE-2026-5394
Mitre link : CVE-2026-5394
CVE.ORG link : CVE-2026-5394
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
