THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-79cw-hfcc-7mw9 (high) — Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes

[GHSA] GHSA-79cw-hfcc-7mw9 (high) — Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes

medgithub_advisoriesPublished 2026-08-28

GHSA-79cw-hfcc-7mw9 Severity: high CVE: CVE-2026-55208

Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes

## Summary

An authenticated user extracts the admin password hash and any other database content through a time-based blind SQL injection in the `DateFilter` column key parameter. The `POST /pimco

Indicators of compromise

Original source: https://github.com/advisories/GHSA-79cw-hfcc-7mw9