Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:42144
HistoryAug 05, 2023 - 3:43 a.m.

Path Traversal

2023-08-0503:43:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
pimcore
vulnerability
assetcontroller::importserverfilesaction
path traversal
file alteration
illegal access
dos

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

38.3%

pimcore/pimcore is vulnerable to Path Traversal. A path traversal flaw exists in AssetController::importServerFilesAction, which allows an attacker to alter the pimcore_log argument, possibly overwriting or modifying sensitive files. This might also lead to illegal access, privilege escalation, or the exposure of sensitive information. Furthermore, if vital system files are changed or destroyed, it may result in a denial of service (DoS).

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

38.3%

Related for VERACODE:42144