Show filters
144 Total Results
Displaying 121-130 of 144
Sort by:
Attacker Value
Unknown
CVE-2021-39166
Disclosure Date: September 01, 2021 (last updated February 23, 2025)
Pimcore is an open source data & experience management platform. Prior to version 10.1.2, text-values were not properly escaped before printed in the version preview. This allowed XSS by authenticated users with access to the resources. This issue is patched in Pimcore version 10.1.2.
0
Attacker Value
Unknown
CVE-2021-39170
Disclosure Date: September 01, 2021 (last updated February 23, 2025)
Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets. There is a patch for this issue in Pimcore version 10.1.2. As a workaround, users may apply the patch manually.
0
Attacker Value
Unknown
CVE-2021-37702
Disclosure Date: August 18, 2021 (last updated February 23, 2025)
Pimcore is an open source data & experience management platform. Prior to version 10.1.1, Data Object CSV import allows formular injection. The problem is patched in 10.1.1. Aside from upgrading, one may apply the patch manually as a workaround.
0
Attacker Value
Unknown
CVE-2021-31867
Disclosure Date: July 27, 2021 (last updated February 23, 2025)
Pimcore Customer Data Framework version 3.0.0 and earlier suffers from a Boolean-based blind SQL injection issue in the $id parameter of the SegmentAssignmentController.php component of the application. This issue was fixed in version 3.0.2 of the product.
0
Attacker Value
Unknown
CVE-2021-31869
Disclosure Date: July 27, 2021 (last updated February 23, 2025)
Pimcore AdminBundle version 6.8.0 and earlier suffers from a SQL injection issue in the specificID variable used by the application. This issue was fixed in version 6.9.4 of the product.
0
Attacker Value
Unknown
CVE-2021-23405
Disclosure Date: July 09, 2021 (last updated February 23, 2025)
This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the ClassificationstoreController class.
0
Attacker Value
Unknown
CVE-2021-23340
Disclosure Date: February 18, 2021 (last updated February 22, 2025)
This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAction function of the CustomReportController class (bundles/AdminBundle/Controller/Reports/CustomReportController.php). An authenticated user can reach this function with a GET request at the following endpoint: /admin/reports/custom-report/download-csv?exportFile=&91;filename]. Since exportFile variable is not sanitized, an attacker can exploit a local file inclusion vulnerability.
0
Attacker Value
Unknown
CVE-2020-26246
Disclosure Date: December 03, 2020 (last updated February 22, 2025)
Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create website settings without having the appropriate permissions.
0
Attacker Value
Unknown
CVE-2020-7759
Disclosure Date: October 30, 2020 (last updated February 22, 2025)
The package pimcore/pimcore from 6.7.2 and before 6.8.3 are vulnerable to SQL Injection in data classification functionality in ClassificationstoreController. This can be exploited by sending a specifically-crafted input in the relationIds parameter as demonstrated by the following request: http://vulnerable.pimcore.example/admin/classificationstore/relations?relationIds=[{"keyId"%3a"''","groupId"%3a"'asd'))+or+1%3d1+union+(select+1,2,3,4,5,6,name,8,password,'',11,12,'',14+from+users)+--+"}]
0
Attacker Value
Unknown
CVE-2019-10763
Disclosure Date: November 18, 2019 (last updated November 27, 2024)
pimcore/pimcore before 6.3.0 is vulnerable to SQL Injection. An attacker with limited privileges (classes permission) can achieve a SQL injection that can lead in data leakage. The vulnerability can be exploited via 'id', 'storeId', 'pageSize' and 'tables' parameters, using a payload for trigger a time based or error based sql injection.
0