THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-23rh-xw42-fq82 (high) — Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration

[GHSA] GHSA-23rh-xw42-fq82 (high) — Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration

highgithub_advisoriesPublished 2026-09-10

GHSA-23rh-xw42-fq82 Severity: high CVE: CVE-2026-55416

Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration

# Security Advisory: SQL Injection in Custom Reports via Malicious Report Configuration

## Summary

### Impact

A SQL injection vulnerability exists in the Custom Reports bundle (`bundles/CustomReportsBundle/src/Tool/Adapter/Sql.php:84-135`). An authenticated attack

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-23rh-xw42-fq82