PT-2020-16374 · Pimcore · Pimcore

Brusch

·

Published

2020-12-03

·

Updated

2020-12-03

·

CVE-2020-26246

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pimcore versions prior to 6.8.5
Description The issue allows modification and creation of website settings without appropriate permissions.
Recommendations For versions prior to 6.8.5, update to version 6.8.5 or later to resolve the issue.

Fix

Improper Authorization

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26246
GHSA-7P8P-4253-3MG6

Affected Products

Pimcore