Lucene search

K
cvelistGitHub_MCVELIST:CVE-2023-38708
HistoryAug 04, 2023 - 12:12 a.m.

CVE-2023-38708 Pimcore Path Traversal Vulnerability in AssetController:importServerFilesAction

2023-08-0400:12:33
CWE-22
GitHub_M
www.cve.org
2
pimcore
path traversal
assetcontroller
importserverfilesaction
file overwrite
denial of service
unauthorized access
privilege escalation

6.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

38.3%

Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exists in the AssetController::importServerFilesAction, which allows an attacker to overwrite or modify sensitive files by manipulating the pimcore_log parameter.This can lead to potential denial of service—key file overwrite.
The impact of this vulnerability allows attackers to: overwrite or modify sensitive files, potentially leading to unauthorized access, privilege escalation, or disclosure of confidential information. This could also cause a denial of service (DoS) if critical system files are overwritten or deleted.

CNA Affected

[
  {
    "vendor": "pimcore",
    "product": "pimcore",
    "versions": [
      {
        "version": "< 10.6.7",
        "status": "affected"
      }
    ]
  }
]

6.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

38.3%

Related for CVELIST:CVE-2023-38708