| Summary | An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. This issue affects pimcore: 12.3.3. |
|---|---|
| Publication Date | April 28, 2026, 5:16 a.m. |
| Registration Date | April 29, 2026, 4:07 a.m. |
| Last Update | April 28, 2026, 5:21 a.m. |