The impact of this vulnerability allows attackers to: overwrite or modify sensitive files, potentially leading to unauthorized access, privilege escalation, or disclosure of confidential information. This could also cause a denial of service (DoS) if critical system files are overwritten or deleted.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2190 | Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exists in the `AssetController::importServerFilesAction`, which allows an attacker to overwrite or modify sensitive files by manipulating the pimcore_log parameter.This can lead to potential denial of service---key file overwrite. The impact of this vulnerability allows attackers to: overwrite or modify sensitive files, potentially leading to unauthorized access, privilege escalation, or disclosure of confidential information. This could also cause a denial of service (DoS) if critical system files are overwritten or deleted. |
Github GHSA |
GHSA-34hj-v8fm-x887 | Pimcore Path Traversal Vulnerability in AssetController:importServerFilesAction |
Thu, 03 Oct 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-03T18:21:23.455Z
Reserved: 2023-07-24T16:19:28.366Z
Link: CVE-2023-38708
Updated: 2024-08-02T17:46:56.556Z
Status : Modified
Published: 2023-08-04T01:15:09.890
Modified: 2024-11-21T08:14:05.790
Link: CVE-2023-38708
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA