THREAT OPS › Threat News › [GHSA] GHSA-79cw-hfcc-7mw9 (high) — Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
[GHSA] GHSA-79cw-hfcc-7mw9 (high) — Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
GHSA-79cw-hfcc-7mw9 Severity: high CVE: CVE-2026-55208
Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
## Summary
An authenticated user extracts the admin password hash and any other database content through a time-based blind SQL injection in the `DateFilter` column key parameter. The `POST /pimco
Indicators of compromise
- CVE-2026-55208cve
Original source: https://github.com/advisories/GHSA-79cw-hfcc-7mw9