Information Exposure Through Query Strings Affecting pimcore/pimcore package, versions >=11.0.0-ALPHA1, <11.1.6.1 >=11.2.0, <11.2.2
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.04% (11th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PHP-PIMCOREPIMCORE-6501636
- published 27 Mar 2024
- disclosed 26 Mar 2024
- credit rliebi
Introduced: 26 Mar 2024
CVE-2024-29197 Open this link in a new tabHow to fix?
Upgrade pimcore/pimcore
to version 11.1.6.1, 11.2.2 or higher.
Overview
pimcore/pimcore is a content & product management framework (CMS/PIM/E-Commerce).
Affected versions of this package are vulnerable to Information Exposure Through Query Strings due to improper handling of query arguments in URL requests. An attacker can gain access to unpublished or restricted content by appending ?pimcore_preview=true
to the URL, bypassing the intended access controls that require user authentication.
References
CVSS Scores
version 3.1