Information Exposure Through System Error Message Affecting pimcore/admin-ui-classic-bundle package, versions <1.2.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.66% (47th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-PIMCOREADMINUICLASSICBUNDLE-6062174
  • published16 Nov 2023
  • disclosed15 Nov 2023
  • creditXCapri

Introduced: 15 Nov 2023

CVE-2023-47636  (opens in a new tab)
CWE-209  (opens in a new tab)

How to fix?

Upgrade pimcore/admin-ui-classic-bundle to version 1.2.1 or higher.

Overview

Affected versions of this package are vulnerable to Information Exposure Through System Error Message when the fopen() function is used. This allows a user to view the full path to the webroot. This is achieved by triggering a server response that reveals the full path, such as fopen(/var/www/html/var/tmp/export-{ uniqe id}.csv).

CVSS Base Scores

version 3.1