CVE-2023-2756

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in packagist/pimcore/customer-management-framework-bundle

Identifiers

GHSA-25fx-3c2q-cq46, CVE-2023-2756

Package Slug

packagist/pimcore/customer-management-framework-bundle

Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Description

SQL Injection in GitHub repository pimcore/customer-data-framework prior to 3.3.10.

Affected Versions

All versions before 3.3.10

Solution

Upgrade to version 3.3.10 or above.

Last Modified

2023-05-18

source