{"id":"GHSA-h4ph-crvj-9h92","summary":"Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter","details":"# GitHub Security Advisory Draft — GM-369\n\n## Summary\nSQL injection in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMESTAMP(DATE(FROM_UNIXTIME(...)))` SQL expression without parameterization or allowlist validation.\n\n## Severity\nCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\n\n## Affected Component\n- **Package:** `pimcore/admin-ui-classic-bundle`\n- **File:** `src/Controller/Admin/TranslationController.php`\n- **Lines:** 565 (input), 569 (inadequate sanitization), 593 (injection point)\n- **Endpoint:** `POST /admin/translation/translations`\n\n## Description\nThe translation grid endpoint processes JSON filter parameters. When a filter has `type: \"date\"`, the `property` field is extracted and used to construct a SQL expression:\n\n```php\n$fieldname = $filter[$propertyField];              // Line 565 — user input\n$fieldname = str_replace('--', '', $fieldname);    // Line 569 — trivially bypassable\n$fieldname = $tableName . '.' . $fieldname;        // Line 577\n$fieldname = \"UNIX_TIMESTAMP(DATE(FROM_UNIXTIME({$fieldname})))\";  // Line 593 — injection\n```\n\nThe `str_replace('--', '')` sanitization is trivially bypassable (use `/**/` comments or `----`). In non-language mode, `$fieldname` is concatenated directly into the SQL condition without quoting or parameterization.\n\n## Impact\nAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain.\n\n## Proof of Concept\n```\nPOST /admin/translation/translations\nfilter=[{\"property\":\"1))) UNION SELECT password FROM users WHERE ((1\",\"type\":\"date\",\"operator\":\"eq\",\"value\":\"2026-01-01\"}]\n```\n\n## Suggested Fix\nValidate `$fieldname` against an allowlist of valid column names before SQL interpolation:\n```php\n$allowedDateColumns = ['creationDate', 'modificationDate'];\nif (!in_array($fieldname, $allowedDateColumns, true)) {\n    continue;\n}\n```\n\n## References\n- CWE-89: SQL Injection\n- Related: CVE-2026-27461 (RLIKE injection in Dependency/Dao.php — different code path)\n\n\n---\n\n## Suggested Fix\n\nIn `TranslationController.php`: (1) Add allowlist check for non-language fieldnames before processing. (2) Replace raw string interpolation `UNIX_TIMESTAMP(DATE(FROM_UNIXTIME({$fieldname})))` with `$db-\u003equoteIdentifier($fieldname)` to prevent SQL injection in date filter expressions.\n\n```diff\n--- a/src/Controller/Admin/TranslationController.php\n+++ b/src/Controller/Admin/TranslationController.php\n@@ -569,7 +569,15 @@ class TranslationController extends AdminAbstractController\n                 $fieldname = str_replace('--', '', $fieldname);\n \n                 if (!$languageMode && in_array($fieldname, $validLanguages)\n                     || $languageMode && !in_array($fieldname, $validLanguages)) {\n                     continue;\n                 }\n \n+                // Allowlist non-language fieldnames to prevent SQL injection\n+                $allowedNonLanguageFields = ['key', 'type', 'creationDate', 'modificationDate'];\n+                if (!$languageMode && !in_array($fieldname, $allowedNonLanguageFields) && !in_array($fieldname, $validLanguages)) {\n+                    continue;\n+                }\n+\n                 if (!$languageMode) {\n                     $fieldname = $tableName . '.' . $fieldname;\n                 }\n@@ -582,7 +590,7 @@ class TranslationController extends AdminAbstractController\n                         } elseif ($filter[$operatorField] == 'eq') {\n                             $operator = '=';\n-                            $fieldname = \"UNIX_TIMESTAMP(DATE(FROM_UNIXTIME({$fieldname})))\";\n+                            // Use validated fieldname only — never interpolate raw user input into SQL functions\n+                            $fieldname = sprintf('UNIX_TIMESTAMP(DATE(FROM_UNIXTIME(%s)))', $db-\u003equoteIdentifier($fieldname));\n                         }\n\n```\n\n---\n\n## Proposed Fix\n\n```diff\n--- a/src/Controller/Admin/TranslationController.php\n+++ b/src/Controller/Admin/TranslationController.php\n@@ -569,7 +569,15 @@ class TranslationController extends AdminAbstractController\n                 $fieldname = str_replace('--', '', $fieldname);\n \n                 if (!$languageMode && in_array($fieldname, $validLanguages)\n                     || $languageMode && !in_array($fieldname, $validLanguages)) {\n                     continue;\n                 }\n \n+                // Allowlist non-language fieldnames to prevent SQL injection\n+                $allowedNonLanguageFields = ['key', 'type', 'creationDate', 'modificationDate'];\n+                if (!$languageMode && !in_array($fieldname, $allowedNonLanguageFields) && !in_array($fieldname, $validLanguages)) {\n+                    continue;\n+                }\n+\n                 if (!$languageMode) {\n                     $fieldname = $tableName . '.' . $fieldname;\n                 }\n@@ -582,7 +590,7 @@ class TranslationController extends AdminAbstractController\n                         } elseif ($filter[$operatorField] == 'eq') {\n                             $operator = '=';\n-                            $fieldname = \"UNIX_TIMESTAMP(DATE(FROM_UNIXTIME({$fieldname})))\";\n+                            // Use validated fieldname only — never interpolate raw user input into SQL functions\n+                            $fieldname = sprintf('UNIX_TIMESTAMP(DATE(FROM_UNIXTIME(%s)))', $db-\u003equoteIdentifier($fieldname));\n                         }\n```\n\nHappy to submit this as a PR against a private fork if that is the preferred workflow.","aliases":["CVE-2026-44741"],"modified":"2026-07-10T19:15:11.856742087Z","published":"2026-05-27T00:35:56Z","database_specific":{"github_reviewed_at":"2026-05-27T00:35:56Z","nvd_published_at":null,"cwe_ids":["CWE-89"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/pimcore/pimcore/security/advisories/GHSA-h4ph-crvj-9h92"},{"type":"WEB","url":"https://github.com/pimcore/admin-ui-classic-bundle/pull/1111"},{"type":"WEB","url":"https://github.com/pimcore/admin-ui-classic-bundle/commit/80e57a23d9e19574eddfe9b08e8f26785b2b0d90"},{"type":"WEB","url":"https://github.com/pimcore/admin-ui-classic-bundle/releases/tag/v2.3.6"},{"type":"PACKAGE","url":"https://github.com/pimcore/pimcore"}],"affected":[{"package":{"name":"pimcore/admin-ui-classic-bundle","ecosystem":"Packagist","purl":"pkg:composer/pimcore/admin-ui-classic-bundle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0-RC1"},{"fixed":"2.3.6"}]}],"versions":["2.0.0-RC2","v2.0.0","v2.0.0-RC1","v2.0.0-RC3","v2.0.0-RC4","v2.0.1","v2.0.2","v2.1.0","v2.1.1","v2.1.2","v2.1.3","v2.1.4","v2.2.0","v2.2.1","v2.2.2","v2.2.3","v2.3.0","v2.3.1","v2.3.2","v2.3.3","v2.3.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-h4ph-crvj-9h92/GHSA-h4ph-crvj-9h92.json","last_known_affected_version_range":"\u003c= 2.3.5"}},{"package":{"name":"pimcore/admin-ui-classic-bundle","ecosystem":"Packagist","purl":"pkg:composer/pimcore/admin-ui-classic-bundle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.18"}]}],"versions":["1.4.0","v1.0.0","v1.0.0-BETA1","v1.0.0-RC1","v1.0.0-RC2","v1.0.1","v1.0.2","v1.0.3","v1.0.4","v1.0.5","v1.0.6","v1.1.0","v1.1.0-RC1","v1.1.1","v1.1.2","v1.1.3","v1.1.4","v1.2","v1.2.0-RC1","v1.2.1","v1.2.2","v1.2.3","v1.3.0","v1.3.0-RC1","v1.3.1","v1.3.2","v1.3.3","v1.3.4","v1.3.5","v1.4.1","v1.4.2","v1.4.3","v1.4.4","v1.4.5","v1.5.0","v1.5.0-RC1","v1.5.0-RC2","v1.5.1","v1.5.2","v1.5.3","v1.5.4","v1.5.5","v1.6.0","v1.6.0-RC1","v1.6.0-RC2","v1.6.1","v1.6.2","v1.6.3","v1.6.4","v1.6.5","v1.6.6","v1.7.0","v1.7.1","v1.7.10","v1.7.12","v1.7.13","v1.7.14","v1.7.15","v1.7.16","v1.7.2","v1.7.3","v1.7.4","v1.7.5","v1.7.6","v1.7.7","v1.7.8","v1.7.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-h4ph-crvj-9h92/GHSA-h4ph-crvj-9h92.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}