Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
| Software | From | Fixed in |
|---|---|---|
pimcore / pimcore
|
- | 5.3.0 |