Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-38708

Опубликовано: 04 авг. 2023
Источник: nvd
CVSS3: 6.3
CVSS3: 8.8
EPSS Низкий

Описание

Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exists in the AssetController::importServerFilesAction, which allows an attacker to overwrite or modify sensitive files by manipulating the pimcore_log parameter.This can lead to potential denial of service---key file overwrite. The impact of this vulnerability allows attackers to: overwrite or modify sensitive files, potentially leading to unauthorized access, privilege escalation, or disclosure of confidential information. This could also cause a denial of service (DoS) if critical system files are overwritten or deleted.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pimcore:pimcore:*:*:*:*:*:*:*:*
Версия до 10.6.7 (исключая)

EPSS

Процентиль: 0%
0.00003
Низкий

6.3 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-22
CWE-22

Связанные уязвимости

CVSS3: 6.3
github
больше 2 лет назад

Pimcore Path Traversal Vulnerability in AssetController:importServerFilesAction

EPSS

Процентиль: 0%
0.00003
Низкий

6.3 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-22
CWE-22