vendor:
Pimcore
by:
T. Silpavarangkura, N. Rai-Ngoen, SEC Consult Vulnerability Lab
5.4
CVSS
MEDIUM
SQL Injection, XSS & CSRF
89, 79, 352
CWE
Product Name: Pimcore
Affected Version From: 5.2.3
Affected Version To: 5.3.0
Patch Exists: YES
Related CWE: CVE-2018-14057, CVE-2018-14058, CVE-2018-14059
CPE: pimcore
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2018
SQL Injection, XSS & CSRF vulnerabilities
Multiple SQL injection vulnerabilities have been identified in the REST web service API. An attacker who obtains a valid API key that is granted a necessary permission could successfully perform an attack to extract information from the database. Multiple stored cross-site scripting vulnerabilities have been identified across multiple functions in the application, which allows an authenticated attacker to insert a malicious script into the application. Multiple cross-site request forgery vulnerabilities have been identified across multiple functions in the application, which allows an attacker to perform malicious actions on behalf of the victim.
Mitigation:
The vendor provides a patch for most identified issues, but XSS will not be fixed according to the vendor. An in-depth security analysis performed by security professionals is highly advised, as the software may be affected from further security issues.