VDB
Sign up
HIGH8.8

GHSA-7hqr-j26m-gmwp

Pimcore Unserialize Remote Code Execution

Quick fix

GHSA-7hqr-j26m-gmwp — pimcore/pimcore: upgrade to the fixed version with the command below.

composer require pimcore/pimcore:^5.7.1

Details

An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to `/admin/class/bulk-commit`, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to `bundles/AdminBundle/Controller/Admin/DataObject/ClassController.php`.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/pimcore/pimcore
Introduced in: 0Fixed in: 5.7.1
Fixcomposer require pimcore/pimcore:^5.7.1

References