PT-2023-30526 · Pimcore · Pimcore Admin Classic Bundle
Xcapri
·
Published
2023-11-15
·
Updated
2023-11-22
·
CVE-2023-47636
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Pimcore Admin Classic Bundle versions prior to 1.2.1
Description
The issue allows an attacker to see the path to the webroot/file, which can be used in conjunction with other vulnerabilities, such as SQL Injection using the
load file() query, to view the page source. In the case of Pimcore, the fopen() function does not have an error handle when the file does not exist on the server, causing the server response to reveal the full path, for example, "fopen(/var/www/html/var/tmp/export-{unique id}.csv)".Recommendations
For Pimcore Admin Classic Bundle versions prior to 1.2.1, upgrade to version 1.2.1 to resolve the issue. There are no known workarounds for this vulnerability.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pimcore Admin Classic Bundle