Pimcore Privilege Defined With Unsafe Actions vulnerability
Description
Published by the National Vulnerability Database
May 30, 2023
Published to the GitHub Advisory Database
Jun 6, 2023
Reviewed
Jun 6, 2023
Last updated
Nov 11, 2023
Impact
A new user can privilege escalation to admin role which least config
Patches
Update to version 10.5.23 or apply this patches manually
https://github.com/pimcore/pimcore/commit/c8f37b19c99cd82e4e558857d3e4d5476ea7228a.patch
Workarounds
Apply patches manually: https://github.com/pimcore/pimcore/commit/c8f37b19c99cd82e4e558857d3e4d5476ea7228a.patch
References
https://huntr.dev/bounties/6b2f33d3-2fd0-4d2d-ad7b-2c1e2417eeb1/
References