Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-352x-hc2f-fwff

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Pimcore RCE via PHAR upload

In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the phar://../../../../../../../../var/www/html/web/var/assets/ directory, a different vulnerability than CVE-2019-10867 and CVE-2019-16318.

Пакеты

Наименование

pimcore/pimcore

composer
Затронутые версииВерсия исправления

< 5.7.1

5.7.1

EPSS

Процентиль: 1%
0.00011
Низкий

8.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.8
nvd
больше 6 лет назад

In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the phar://../../../../../../../../var/www/html/web/var/assets/ directory, a different vulnerability than CVE-2019-10867 and CVE-2019-16318.

EPSS

Процентиль: 1%
0.00011
Низкий

8.8 High

CVSS3

Дефекты

CWE-502