SQL injection in Pimcore admin-ui-classic-bundle - CVE-2024-23646

 

SQL injection in Pimcore admin-ui-classic-bundle - CVE-2024-23646

Published: January 24, 2024 / Updated: July 22, 2026


Vulnerability identifier: #VU139123
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-23646
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary SQL statements and escalate privileges.

The vulnerability exists due to SQL injection in the downloadAsZipAddFilesAction endpoint when handling the selectedIds parameter in requests to add files to a zip job. A remote user can send a specially crafted request to execute arbitrary SQL statements and escalate privileges.

The issue affects backend functionality and can be exploited by a logged-in backend user with very basic permissions.


Affected software

Pimcore admin-ui-classic-bundle

How to mitigate CVE-2024-23646

Install security update from vendor's website.

Pimcore admin-ui-classic-bundle - update to 1.3.2

External References

Related Security Bulletins