Vulnerability Database
Blog
FAQ
Docs
CVE-2018-14058
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2018-14058
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14058.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-14058
Aliases
GHSA-q4hw-c66h-4xqc
Published
2018-08-17T18:29:00Z
Modified
2024-09-03T02:05:49.819822Z
Severity
6.5 (Medium)
CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Calculator
Summary
[none]
Details
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
References
http://packetstormsecurity.com/files/148954/Pimcore-5.2.3-CSRF-Cross-Site-Scripting-SQL-Injection.html
https://www.exploit-db.com/exploits/45208/
https://www.sec-consult.com/en/blog/advisories/sql-injection-xss-csrf-vulnerabilities-in-pimcore-software/
http://seclists.org/fulldisclosure/2018/Aug/13
Affected packages
Git
/
github.com/pimcore/pimcore
Affected ranges
Type
GIT
Repo
https://github.com/pimcore/pimcore
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
6642d20155a5166ab523641a9fd70a2da99e73f4
Affected versions
2.*
2.2.0
2.2.1
2.2.2
2.3.0
3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.1.1
4.*
4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.3.0
4.3.1
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
v5.*
v5.0.0
v5.0.0-RC
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.1.0
v5.1.0-alpha
v5.1.1
v5.1.2
v5.1.3
v5.2.0
v5.2.3
CVE-2018-14058 - OSV