Skip to content
Threat Feed

Tag

Pimcore

4 briefs RSS
high advisory

Pimcore Unrestricted Deserialization via Object-Store Columns

Pimcore components including Hotspotimage, ImageGallery, Block, and Video perform insecure PHP deserialization on database-stored metadata, enabling remote code execution via object injection.

Pimcore php-injection deserialization rce
1t
high advisory

SQL Injection in Pimcore via ClassDefinition UID

An improper input validation in Pimcore's ClassDefinition UID and unsanitized SQL query construction allow authenticated users to perform UNION-based SQL injection and exfiltrate database contents.

Pimcore web-vulnerability sqli
1r 1t
high advisory

Pimcore Platform SQL Injection in DataObject Composite Index Handling

A SQL injection vulnerability exists in Pimcore Platform when handling DataObject composite indices during class definition import/save, allowing an authenticated administrative user to inject attacker-controlled composite index metadata, leading to unintended SQL execution in the backend, specifically via the `index_columns` element.

pimcore/pimcore sql-injection web-application pimcore
2r 1t 1c
high advisory

Pimcore WebDAV Asset MOVE Missing Authorization Vulnerability

Pimcore's WebDAV asset endpoint exposes a `MOVE` operation without authentication, allowing unauthenticated remote attackers to delete assets if they know two existing asset paths in the same directory; Authenticated low-privileged users may also be able to perform unauthorized asset move or overwrite operations because the move path does not enforce `rename`, `delete`, `create`, or `publish` permissions, leading to data loss, content integrity loss, and service disruption.

pimcore/pimcore webdav asset-management missing-authorization pimcore
2r 2t