LiveActive security incident?Get immediate response
CVE Record

CVE-2022-31092: SQL injection in pimcore

Pimcore is an Open Source Data & Experience Management Platform. Pimcore offers developers listing classes to make querying data easier. This listing classes also allow to order or group the results based on one or more columns which should be quoted by default. The actual issue is that quoting is not done properly in both cases, so there's the theoretical possibility to inject custom SQL if the developer is using this methods with input data and not doing proper input validation in advance and so relies on the auto-quoting being done by the listing classes. This issue has been resolved in version 10.4.4. Users are advised to upgrade or to apple the patch manually. There are no known workarounds for this issue.

HighCVSS 7.5Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Pimcore before 10.4.4 could mishandle SQL quoting when applications use listing classes to sort or group results. If a developer passed user-controlled values into those methods without validation, an authenticated attacker could potentially alter database queries. The vendor fixed it in 10.4.4 and states there are no known workarounds.

Executive priority

Prioritize remediation for internet-facing or business-critical Pimcore systems, especially where authenticated users can search, filter, sort, or group data. The risk is high because successful SQL injection can affect confidentiality, integrity, and availability, but exploitation depends on application-specific usage.

Technical view

CVE-2022-31092 is CWE-89 SQL injection in Pimcore listing-class order and group handling. The issue is improper quoting of column inputs, creating a theoretical injection path when application code trusts auto-quoting for user-provided ordering or grouping data. CVSS 3.1 is 7.5 with network attack vector, high complexity, and low privileges required.

Likely exposure

Exposure is most likely in Pimcore deployments below 10.4.4 with custom features that let authenticated users influence sorting or grouping parameters. The source bundle lists Pimcore only, with no CPEs and no evidence of broader affected products.

Exploitation context

The source bundle does not show active exploitation, and KEV is false. Exploitation appears conditional: an attacker needs low privileges and a vulnerable application path where user input reaches listing-class order or group methods without proper validation.

Researcher notes

Focus review on application paths that pass user-controlled field names into listing-class ordering or grouping. The vendor frames the bug as improper auto-quoting, not every Pimcore installation being directly exploitable. Avoid assuming exploitability without confirming vulnerable code paths.

Mitigation direction

  • Upgrade Pimcore to version 10.4.4 or later.
  • If upgrade is blocked, apply the vendor patch manually.
  • Review vendor advisory before choosing any temporary compensating controls.
  • Allowlist valid sort and group fields in application code.
  • Do not treat input validation as a substitute for the vendor fix.

Validation and detection

  • Inventory all Pimcore instances and confirm versions are 10.4.4 or later.
  • Review custom code using Pimcore listing classes for order or group operations.
  • Check whether request parameters can influence sorting or grouping values.
  • Confirm the vendor patch commit is present if manually patched.
  • Add regression tests for rejected invalid sort and group fields.
Prepared
Confidence
high
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-89: Database access and collection lookup

Injection into data stores can inform collection, data access, and exfiltration detection reviews. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Database behavior lookup

The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2022-31092 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.5 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.5CVSS 3.1HighCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H1.65.9Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

7.5High
CVSS 3.1 vector shape for CVE-2022-31092Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
pimcorepimcore< 10.4.4Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-89 · source CWE mapping

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.