CVE-2024-11956

Source
https://cve.org/CVERecord?id=CVE-2024-11956
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11956.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-11956
Aliases
Published
2025-01-28T13:46:27.639Z
Modified
2026-07-15T01:49:14.380272037Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Pimcore customer-data-framework list sql injection
Details

A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unknown functionality of the file /admin/customermanagementframework/customers/list. The manipulation of the argument filterDefinition/filter leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/11xxx/CVE-2024-11956.json",
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-74",
        "CWE-89"
    ]
}
References

Affected packages

Git / github.com/pimcore/customer-data-framework

Affected ranges

Type
GIT
Repo
https://github.com/pimcore/customer-data-framework
Events
Database specific
{
    "cpe": "cpe:2.3:a:pimcore:pimcore:*:*:*:*:*:*:*:*",
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "4.0"
        },
        {
            "last_affected": "4.0"
        },
        {
            "introduced": "4.1"
        },
        {
            "last_affected": "4.1"
        },
        {
            "introduced": "4.2"
        },
        {
            "last_affected": "4.2"
        },
        {
            "introduced": "0"
        },
        {
            "fixed": "4.2.1"
        }
    ]
}

Affected versions

4.*
4.0
4.1
4.2
v4.*
v4.0.0
v4.1.0
v4.1.1
v4.1.2
v4.2.0
v4.2.0-RC1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11956.json"