Описание
Pimcore Remote Code Execution vulnerability in Search function
Impact
Attacker can get full DB and maybe RCE knowing the WEBROOT path
Patches
Update to version 10.5.19 or apply this patch manually https://github.com/pimcore/pimcore/commit/367b74488808d71ec3f66f4ca9e8df5217c2c8d2.patch
Workarounds
Apply patch https://github.com/pimcore/pimcore/commit/367b74488808d71ec3f66f4ca9e8df5217c2c8d2.patch manually.
References
#14538
Ссылки
- https://github.com/pimcore/pimcore/security/advisories/GHSA-42c3-wvww-gcqj
- https://nvd.nist.gov/vuln/detail/CVE-2023-1578
- https://github.com/pimcore/pimcore/pull/14538
- https://github.com/pimcore/pimcore/commit/367b74488808d71ec3f66f4ca9e8df5217c2c8d2
- https://huntr.dev/bounties/7e441a14-8e55-4ab4-932c-4dc56bb1bc2e
Пакеты
Наименование
pimcore/pimcore
composer
Затронутые версииВерсия исправления
< 10.5.19
10.5.19
Связанные уязвимости
CVSS3: 8.8
nvd
почти 3 года назад
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.