mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-25 12:44:05 +02:00
805 B
805 B
CVE-2021-23405
Description
This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the ClassificationstoreController class.
POC
Reference
- https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-1316297
- https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-1316297
Github
No PoCs found on GitHub currently.