CVE-2022-1339 Information

Description

SQL injection in ElementController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Reference

https://huntr.dev/bounties/ae8dc737-844e-40da-a9f7-e72d8e50f6f9 https://github.com/pimcore/pimcore/commit/adae3be64427466bf0df15ceaea2ac30da93752c

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

7.5

Share on: