HIGH
An issue was discovered in Pimcore before 5.7.1
Published Apr 4, 2019
8.8
HIGHCVSS 3.0
EPSS 68.87%
Description
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to bundles/AdminBundle/Controller/Admin/DataObject/ClassController.php.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://packetstormsecurity.com/files/152667/Pimcore-Unserialize-Remote-Code-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://www.rapid7.com/db/modules/exploit/multi/http/pimcore_unserialize_rce x_refsource_MISCThird Party Advisory
- https://blog.certimetergroup.com/it/articolo/security/polyglot_phar_deserialization_to_rce x_refsource_MISC
- https://github.com/advisories/GHSA-7hqr-j26m-gmwp Advisory
- https://github.com/pimcore/pimcore/commit/38a29e2f4f5f060a73974626952501cee05fda73 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10867
- https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-173998 x_refsource_MISCExploitThird Party Advisory
- https://www.exploit-db.com/exploits/46783 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/152667/Pimcore-Unserialize-Remote-Code-Execution.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| http://www.rapid7.com/db/modules/exploit/multi/http/pimcore_unserialize_rce | x_refsource_MISCThird Party Advisory | |
| https://blog.certimetergroup.com/it/articolo/security/polyglot_phar_deserialization_to_rce | x_refsource_MISC | |
| https://github.com/advisories/GHSA-7hqr-j26m-gmwp | Advisory | |
| https://github.com/pimcore/pimcore/commit/38a29e2f4f5f060a73974626952501cee05fda73 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-10867 | ||
| https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-173998 | x_refsource_MISCExploitThird Party Advisory | |
| https://www.exploit-db.com/exploits/46783 | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 4, 2019
Updated Aug 4, 2024
Reserved Apr 4, 2019
Link CVE-2019-10867
CISA Vulnrichment
GHSA-7HQR-J26M-GMWP Updated n/a