logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-23646

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-23646

Description:
Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The application allows users to create zip files from available files on the site. In the 1.x branch prior to version 1.3.2, parameter `selectedIds` is susceptible to SQL Injection. Any backend user with very basic permissions can execute arbitrary SQL statements and thus alter any data or escalate their privileges to at least admin level. Version 1.3.2 contains a fix for this issue.
Last updated date:
01/31/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
01/31/2024
Reference url to background

https://github.com/pimcore/admin-ui-classic-bundle/security/advisories/GHSA-cwx6-4wmf-c6xv

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy