VDB
Sign up
HIGH8.8

GHSA-352x-hc2f-fwff

Pimcore RCE via PHAR upload

Quick fix

GHSA-352x-hc2f-fwff — pimcore/pimcore: upgrade to the fixed version with the command below.

composer require pimcore/pimcore:^5.7.1

Details

In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a `phar://` URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the `phar://../../../../../../../../var/www/html/web/var/assets/` directory, a different vulnerability than CVE-2019-10867 and CVE-2019-16318.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/pimcore/pimcore
Introduced in: 0Fixed in: 5.7.1
Fixcomposer require pimcore/pimcore:^5.7.1

References