8.8 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
0.001 Low
EPSS
Percentile
38.3%
pimcore/pimcore is vulnerable to Path Traversal. A path traversal flaw exists in AssetController::importServerFilesAction
, which allows an attacker to alter the pimcore_log argument
, possibly overwriting or modifying sensitive files. This might also lead to illegal access, privilege escalation, or the exposure of sensitive information. Furthermore, if vital system files are changed or destroyed, it may result in a denial of service (DoS).
CPE | Name | Operator | Version |
---|---|---|---|
pimcore/pimcore | le | v10.6.6 | |
pimcore/pimcore | le | v10.6.6 |