HIGH8.8
GHSA-352x-hc2f-fwff
Pimcore RCE via PHAR upload
Quick fix
GHSA-352x-hc2f-fwff — pimcore/pimcore: upgrade to the fixed version with the command below.
composer require pimcore/pimcore:^5.7.1Details
In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a `phar://` URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the `phar://../../../../../../../../var/www/html/web/var/assets/` directory, a different vulnerability than CVE-2019-10867 and CVE-2019-16318.
Are you affected?
Enter the version of the package you're using.