CVE-2018-14058

MEDIUM

Pimcore <5.3.0 - SQL Injection

Title source: llm

Description

Pimcore before 5.3.0 allows SQL Injection via the REST web service API.

Exploits (2)

metasploit WORKING POC
by Thongchai Silpavarangkura, N. Rai-Ngoen, Shelby Pace · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/pimcore_creds_sqli.rb
exploitdb WRITEUP
by SEC Consult · textwebappsphp
https://www.exploit-db.com/exploits/45208

Scores

CVSS v3 6.5
EPSS 0.0151
EPSS Percentile 80.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-89
Status published

Affected Products (2)

pimcore/pimcore < 5.3.0
pimcore/pimcore < 5.3.0Packagist

Timeline

Published Aug 17, 2018
Tracked Since Feb 18, 2026