Vulnerability Description
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to bundles/AdminBundle/Controller/Admin/DataObject/ClassController.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pimcore | Pimcore | < 5.7.1 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/152667/Pimcore-Unserialize-Remote-Code-ExecExploitThird Party AdvisoryVDB Entry
- http://www.rapid7.com/db/modules/exploit/multi/http/pimcore_unserialize_rceThird Party Advisory
- https://blog.certimetergroup.com/it/articolo/security/polyglot_phar_deserializat
- https://github.com/pimcore/pimcore/commit/38a29e2f4f5f060a73974626952501cee05fdaPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-173998ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/46783/ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/152667/Pimcore-Unserialize-Remote-Code-ExecExploitThird Party AdvisoryVDB Entry
- http://www.rapid7.com/db/modules/exploit/multi/http/pimcore_unserialize_rceThird Party Advisory
- https://blog.certimetergroup.com/it/articolo/security/polyglot_phar_deserializat
- https://github.com/pimcore/pimcore/commit/38a29e2f4f5f060a73974626952501cee05fdaPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-173998ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/46783/ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2019-10867?
CVE-2019-10867 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize functio...
How severe is CVE-2019-10867?
CVE-2019-10867 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10867?
Check the references section above for vendor advisories and patch information. Affected products include: Pimcore Pimcore.