First published: Fri Apr 22 2022(Updated: )
SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6. This vulnerability is capable of steal the data
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Pimcore Pimcore | <10.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-1429 is high with a CVSS score of 7.5.
CVE-2022-1429 can be exploited through SQL injection in GridHelperService.php in the Pimcore/Pimcore GitHub repository.
The affected software of CVE-2022-1429 is Pimcore prior to version 10.3.6.
Yes, the fix for CVE-2022-1429 is available in version 10.3.6 of Pimcore.
The CWE category of CVE-2022-1429 is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).