Pimcore Vulnerable to PHP Object Injection Attacks
High severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Aug 16, 2023
Description
Published by the National Vulnerability Database
Apr 21, 2014
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Aug 16, 2023
Last updated
Aug 16, 2023
The
getObjectByToken
function inNewsletter.php
in thePimcore_Tool_Newsletter
module in pimcore 1.4.9 through 2.0.0 does not properly handle an object obtained by unserializing Lucene search data, which allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via vectors involving aZend_Pdf_ElementFactory_Proxy
object and a pathname with a trailing\0
character.References