Vulnerability Description
Pimcore AdminBundle version 6.8.0 and earlier suffers from a SQL injection issue in the specificID variable used by the application. This issue was fixed in version 6.9.4 of the product.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pimcore | Pimcore | < 6.9.4 |
Related Weaknesses (CWE)
References
- https://www.rapid7.com/blog/post/2021/07/27/multiple-open-source-web-app-vulneraExploitThird Party Advisory
- https://www.rapid7.com/blog/post/2021/07/27/multiple-open-source-web-app-vulneraExploitThird Party Advisory
FAQ
What is CVE-2021-31869?
CVE-2021-31869 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Pimcore AdminBundle version 6.8.0 and earlier suffers from a SQL injection issue in the specificID variable used by the application. This issue was fixed in version 6.9.4 of the product.
How severe is CVE-2021-31869?
CVE-2021-31869 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-31869?
Check the references section above for vendor advisories and patch information. Affected products include: Pimcore Pimcore.