PT-2023-31900 · Pimcore · Pimcore

Published

2023-09-26

·

Updated

2023-09-29

·

CVE-2023-5192

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions pimcore/demo versions prior to 10.3.0
Description The issue concerns excessive data query operations in a large data table. Additionally, introspection is enabled on the demo site demo.pimcore.fun, which allows users to run introspection queries. This presents a potential schema information disclosure risk due to the exposure of schema details through GraphQL, a feature available for users on the demo site.
Recommendations For versions prior to 10.3.0, update to version 10.3.0 or later to resolve the issue. As a temporary workaround, consider disabling the GraphQL feature on the demo site to minimize the risk of schema information disclosure. Restrict access to introspection queries on demo.pimcore.fun to prevent potential misuse.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-5192
GHSA-P76J-H4M8-HX5C

Affected Products

Pimcore