HIGH8.8
GHSA-7hqr-j26m-gmwp
Pimcore Unserialize Remote Code Execution
Quick fix
GHSA-7hqr-j26m-gmwp — pimcore/pimcore: upgrade to the fixed version with the command below.
composer require pimcore/pimcore:^5.7.1Details
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to `/admin/class/bulk-commit`, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to `bundles/AdminBundle/Controller/Admin/DataObject/ClassController.php`.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-10867[ADVISORY]
- https://github.com/pimcore/pimcore/commit/38a29e2f4f5f060a73974626952501cee05fda73[WEB]
- https://blog.certimetergroup.com/it/articolo/security/polyglot_phar_deserialization_to_rce[WEB]
- https://github.com/pimcore/pimcore[PACKAGE]
- https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-173998[WEB]
- https://www.exploit-db.com/exploits/46783[WEB]
- http://packetstormsecurity.com/files/152667/Pimcore-Unserialize-Remote-Code-Execution.html[WEB]
- http://www.rapid7.com/db/modules/exploit/multi/http/pimcore_unserialize_rce[WEB]