Headline
GHSA-42c3-wvww-gcqj: Pimcore Remote Code Execution vulnerability in Search function
Impact
Attacker can get full DB and maybe RCE knowing the WEBROOT path
Patches
Update to version 10.5.19 or apply this patch manually https://github.com/pimcore/pimcore/commit/367b74488808d71ec3f66f4ca9e8df5217c2c8d2.patch
Workarounds
Apply patch https://github.com/pimcore/pimcore/commit/367b74488808d71ec3f66f4ca9e8df5217c2c8d2.patch manually.
References
#14538
Pimcore Remote Code Execution vulnerability in Search function
Moderate severity GitHub Reviewed Published Mar 22, 2023 in pimcore/pimcore • Updated Mar 22, 2023
Related news
CVE-2023-1578
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.