CVE-2024-23646 HIGH

CVE-2024-23646: Pimcore Admin Classic Bundle SQL Injection in Admin download files as zip

Vendor Pimcore
Product admin-ui-classic-bundle
Weakness CWE-89 · SQLi
Published January 24, 2024
Last update May 30, 2025

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The application allows users to create zip files from available files on the site. In the 1.x branch prior to version 1.3.2, parameter `selectedIds` is susceptible to SQL Injection. Any backend user with very basic permissions can execute arbitrary SQL statements and thus alter any data or escalate their privileges to at least admin level. Version 1.3.2 contains a fix for this issue.

Key dates

02Disclosure timeline

January 24, 2024 CVE published
May 30, 2025 Record updated