PT-2023-31900 · Pimcore · Pimcore

CVE-2023-5192

·

Publicado

2023-09-26

·

Atualizado

2023-09-29

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions pimcore/demo versions prior to 10.3.0
Description The issue concerns excessive data query operations in a large data table. Additionally, introspection is enabled on the demo site demo.pimcore.fun, which allows users to run introspection queries. This presents a potential schema information disclosure risk due to the exposure of schema details through GraphQL, a feature available for users on the demo site.
Recommendations For versions prior to 10.3.0, update to version 10.3.0 or later to resolve the issue. As a temporary workaround, consider disabling the GraphQL feature on the demo site to minimize the risk of schema information disclosure. Restrict access to introspection queries on demo.pimcore.fun to prevent potential misuse.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-5192
GHSA-P76J-H4M8-HX5C

Produtos afetados

Pimcore