CVE-2015-4425 Information
Feb 14, 2021
cve
Description
Directory traversal vulnerability in pimcore before build 3473 allows remote authenticated users with the \assets\ permission to create or write to arbitrary files via a .. (dot dot) in the dir parameter to admin/asset/add-asset-compatibility.
Reference
http://seclists.org/fulldisclosure/2015/Jul/57 https://github.com/pimcore/pimcore/commit/4f2a95f877d406a054f9f2253475fe58c76aa03d https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2015-4425/
Share on: