CVE-2015-4426

pimcore < build 3473 - SQL Injection via Admin Asset Grid-Proxy Filter Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in pimcore before build 3473 allows remote attackers to execute arbitrary SQL commands via the filter parameter to admin/asset/grid-proxy.

References (4)

Core 4

Scores

EPSS 0.0210
EPSS Percentile 79.3%

Details

CWE
CWE-89
Status published
Products (1)
pimcore/pimcore
Published Aug 18, 2015
Tracked Since Feb 18, 2026