Описание
Pimcore Demo Allows GraphQL Introspection
Introspection is enabled on demo.pimcore.fun. The demo site has graphql as a feature for users, but allows users to run instropection queries, which presents a potential schema information disclosure vulnerability.
Пакеты
Наименование
pimcore/demo
composer
Затронутые версииВерсия исправления
< 10.3.0
10.3.0
Связанные уязвимости
CVSS3: 6.5
nvd
больше 2 лет назад
Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0.