HIGH7.1
GHSA-h7f9-cvh5-qw7f
Path traversal in pimcore/pimcore
Quick fix
GHSA-h7f9-cvh5-qw7f — pimcore/pimcore: upgrade to the fixed version with the command below.
composer require pimcore/pimcore:^6.8.8Details
This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAction function of the CustomReportController class (bundles/AdminBundle/Controller/Reports/CustomReportController.php). An authenticated user can reach this function with a GET request at the following endpoint: /admin/reports/custom-report/download-csv?exportFile=&91;filename]. Since exportFile variable is not sanitized, an attacker can exploit a local file inclusion vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23340[ADVISORY]
- https://github.com/pimcore/pimcore/commit/1786bdd4962ee51544fad537352c2b4223309442[WEB]
- https://github.com/pimcore/pimcore/blob/v6.7.2/bundles/AdminBundle/Controller/Reports/CustomReportController.php%23L454[WEB]
- https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-1070132[WEB]