Описание
Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in Pimcore/Mail & ClassDefinition\Layout\Text is vulnerable to server-side template injection, which could lead to remote code execution. Version 10.5.9 contains a patch for this issue. As a workaround, one may apply the patch manually.
Ссылки
- PatchThird Party Advisory
- Issue TrackingPatchThird Party Advisory
- Mailing ListPatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Issue TrackingPatchThird Party Advisory
- Mailing ListPatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 10.5.9 (исключая)
cpe:2.3:a:pimcore:pimcore:*:*:*:*:*:*:*:*
EPSS
Процентиль: 42%
0.00205
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-94
CWE-94
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
RCE vulnerability in Pimcore/Mail & Dynamic Text Layout
EPSS
Процентиль: 42%
0.00205
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-94
CWE-94