Vulnerabilities
Vulnerable Software
Pimcore:  >> Pimcore  >> 6.2.3  Security Vulnerabilities
pimcore/pimcore before 6.3.0 is vulnerable to SQL Injection. An attacker with limited privileges (classes permission) can achieve a SQL injection that can lead in data leakage. The vulnerability can be exploited via 'id', 'storeId', 'pageSize' and 'tables' parameters, using a payload for trigger a time based or error based sql injection.
CVSS Score
6.5
EPSS Score
0.0
Published
2019-11-18
bundles/AdminBundle/Controller/Admin/EmailController.php in Pimcore before 6.3.0 allows script execution in the Email Log preview window because of the lack of a Content-Security-Policy header.
CVSS Score
6.1
EPSS Score
0.0
Published
2019-11-15
Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translations.js mishandles certain HTML elements.
CVSS Score
6.1
EPSS Score
0.0
Published
2019-10-31


Contact Us

Shodan ® - All rights reserved