Information Exposure Through System Error Message Affecting pimcore/admin-ui-classic-bundle package, versions <1.2.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of concept
EPSS
0.09% (40th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Information Exposure Through System Error Message vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-PIMCOREADMINUICLASSICBUNDLE-6062174
  • published16 Nov 2023
  • disclosed15 Nov 2023
  • creditXCapri

Introduced: 15 Nov 2023

CVE-2023-47636  (opens in a new tab)
CWE-209  (opens in a new tab)

How to fix?

Upgrade pimcore/admin-ui-classic-bundle to version 1.2.1 or higher.

Overview

Affected versions of this package are vulnerable to Information Exposure Through System Error Message when the fopen() function is used. This allows a user to view the full path to the webroot. This is achieved by triggering a server response that reveals the full path, such as fopen(/var/www/html/var/tmp/export-{ uniqe id}.csv).

CVSS Scores

version 3.1