THREAT OPS › Threat News › [GHSA] GHSA-23rh-xw42-fq82 (high) — Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration
[GHSA] GHSA-23rh-xw42-fq82 (high) — Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration
GHSA-23rh-xw42-fq82 Severity: high CVE: CVE-2026-55416
Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration
# Security Advisory: SQL Injection in Custom Reports via Malicious Report Configuration
## Summary
### Impact
A SQL injection vulnerability exists in the Custom Reports bundle (`bundles/CustomReportsBundle/src/Tool/Adapter/Sql.php:84-135`). An authenticated attack
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-55416cve
- https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.htmlurl
Original source: https://github.com/advisories/GHSA-23rh-xw42-fq82