Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h7f9-cvh5-qw7f

Опубликовано: 25 фев. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

Path traversal in pimcore/pimcore

This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAction function of the CustomReportController class (bundles/AdminBundle/Controller/Reports/CustomReportController.php). An authenticated user can reach this function with a GET request at the following endpoint: /admin/reports/custom-report/download-csv?exportFile=&91;filename]. Since exportFile variable is not sanitized, an attacker can exploit a local file inclusion vulnerability.

Пакеты

Наименование

pimcore/pimcore

composer
Затронутые версииВерсия исправления

< 6.8.8

6.8.8

EPSS

Процентиль: 5%
0.00022
Низкий

7.1 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.1
nvd
почти 5 лет назад

This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAction function of the CustomReportController class (bundles/AdminBundle/Controller/Reports/CustomReportController.php). An authenticated user can reach this function with a GET request at the following endpoint: /admin/reports/custom-report/download-csv?exportFile=&91;filename]. Since exportFile variable is not sanitized, an attacker can exploit a local file inclusion vulnerability.

EPSS

Процентиль: 5%
0.00022
Низкий

7.1 High

CVSS3

Дефекты

CWE-22