PT-2023-19308 · Pimcore · Pimcore

Dvesh3

·

Publicado

2023-02-02

·

Atualizado

2023-02-13

·

CVE-2023-23937

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Pimcore versions prior to 10.5.16
Description The upload functionality for updating user profiles does not properly validate the file content-type, allowing any authenticated user to bypass this security check by adding a valid signature (e.g., GIF89) and sending any invalid content-type. This could allow an authenticated attacker to upload HTML files with JS content that will be executed in the context of the domain.
Recommendations For versions prior to 10.5.16, update to version 10.5.16 to resolve the issue. As a temporary workaround, consider restricting the upload functionality for updating user profiles until the update is applied.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-23937
GHSA-8XV4-JJ4H-QWW6

Produtos afetados

Pimcore