Vulnerability record · CVE-2023-1578 · published 22 March 2023
CVE-2023-1578: Pimcore SQL injection before 10.5.19
Pimcore · Pimcore
Pimcore versions prior to 10.5.19 contain a SQL injection flaw (CWE-89) in the GitHub repository pimcore/pimcore. A low-privileged authenticated user can inject SQL through a network-reachable interface, which matters because it can compromise the confidentiality, integrity and availability of the underlying database.
Description
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with high EPSS and a public exploit reference, though exploitation requires an authenticated low-privileged account.
What it is
Pimcore versions prior to 10.5.19 contain a SQL injection flaw (CWE-89) in the GitHub repository pimcore/pimcore. A low-privileged authenticated user can inject SQL through a network-reachable interface, which matters because it can compromise the confidentiality, integrity and availability of the underlying database.
Impact
An attacker with a low-privileged account can read, modify or delete database contents and potentially disrupt the application, given the high confidentiality, integrity and availability impact in the CVSS vector.
Attack surface
Reachable over the network (AV:N) with low attack complexity and no user interaction, but it requires a low-privileged authenticated account (PR:L).
Exploitation
Not listed in CISA KEV, but EPSS is 0.62755 (99.157th percentile) and the references include an Exploit-tagged third-party advisory, indicating public exploit information exists.
What to do
- Upgrade Pimcore to 10.5.19 or later, applying the patch commit 367b74488808d71ec3f66f4ca9e8df5217c2c8d2.
- Restrict network access to Pimcore administrative and application interfaces to trusted users.
- Review and minimize accounts with low-privileged access, and enforce least privilege.
- Audit database accounts used by Pimcore and remove unnecessary write or DDL permissions.
Detection
- Monitor database and application logs for SQL syntax errors or anomalous query patterns from authenticated sessions.
- Alert on unexpected bulk reads, writes or schema changes originating from Pimcore application accounts.
- Review access logs for unusual authenticated activity against Pimcore endpoints that handle user-supplied input.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/pimcore/pimcore/commit/367b74488808d71ec3f66f4ca9e8df5217c2c8d2 | Patch |
| https://huntr.dev/bounties/7e441a14-8e55-4ab4-932c-4dc56bb1bc2e | ExploitPatchThird Party Advisory |
| https://github.com/pimcore/pimcore/commit/367b74488808d71ec3f66f4ca9e8df5217c2c8d2 | Patch |
| https://huntr.dev/bounties/7e441a14-8e55-4ab4-932c-4dc56bb1bc2e | ExploitPatchThird Party Advisory |
Track CVE-2023-1578 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-1578), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.