CVE-2023-28438 - CVE House
Back to Database
Status published Medium CVE-2023-28438

Pimcore vulnerable to improper quoting of filters in Custom Reports

Vulnerability Description

Pimcore is an open source data and experience management platform. Prior to version 10.5.19, since a user with 'report' permission can already write arbitrary SQL queries and given the fact that this endpoint is using the GET method (no CSRF protection), an attacker can inject an arbitrary query by manipulating a user to click on a link. Users should upgrade to version 10.5.19 to receive a patch or, as a workaround, may apply the patch manually.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-28438

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

pimcore
Vulnerable Versions:
< 10.5.19

Timeline

Official Publish: March 22nd, 2023
Last Modified: February 25th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N

Weaknesses (CWE)