Home / Companies / Sonar / Blog / Post Details
Content Deep Dive

Pimcore: One click, two security vulnerabilities

Blog post from Sonar

Post Details
Company
Date Published
Author
Yaniv Nizry
Word Count
1,577
Company Posts That Month
13
Language
English
Hacker News Points
-
Post removed?
No
Summary

The Pimcore Platform, used by over 100,000 clients across 56 countries, has two vulnerabilities that can be exploited with a single GET request. The first vulnerability is a path traversal issue in the create-csv endpoint, which allows an attacker to control the extension and folder path of a CSV file. The second vulnerability is an SQL injection vulnerability in the getData function, which enables an attacker to inject malicious SQL code into the query. By combining these two vulnerabilities, an attacker can create a malicious link that will deploy a web shell on the server. Both vulnerabilities were fixed in Pimcore version 10.5.19.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.