PT-2023-31900 · Pimcore · Pimcore
Published
2023-09-26
·
Updated
2023-09-29
·
CVE-2023-5192
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pimcore/demo versions prior to 10.3.0
Description
The issue concerns excessive data query operations in a large data table. Additionally, introspection is enabled on the demo site
demo.pimcore.fun, which allows users to run introspection queries. This presents a potential schema information disclosure risk due to the exposure of schema details through GraphQL, a feature available for users on the demo site.Recommendations
For versions prior to 10.3.0, update to version 10.3.0 or later to resolve the issue.
As a temporary workaround, consider disabling the GraphQL feature on the demo site to minimize the risk of schema information disclosure.
Restrict access to introspection queries on
demo.pimcore.fun to prevent potential misuse.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pimcore