Логотип exploitDog
bind:CVE-2019-10867
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-10867

Количество 2

Количество 2

nvd логотип

CVE-2019-10867

почти 7 лет назад

An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to bundles/AdminBundle/Controller/Admin/DataObject/ClassController.php.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-7hqr-j26m-gmwp

больше 3 лет назад

Pimcore Unserialize Remote Code Execution

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-10867

An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to bundles/AdminBundle/Controller/Admin/DataObject/ClassController.php.

CVSS3: 8.8
54%
Средний
почти 7 лет назад
github логотип
GHSA-7hqr-j26m-gmwp

Pimcore Unserialize Remote Code Execution

CVSS3: 8.8
54%
Средний
больше 3 лет назад

Уязвимостей на страницу