This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAction function of the CustomReportController class (bundles/AdminBundle/Controller/Reports/CustomReportController.php). An authenticated user can reach this function with a GET request at the following endpoint: /admin/reports/custom-report/download-csv?exportFile=&91;filename]. Since exportFile variable is not sanitized, an attacker can exploit a local file inclusion vulnerability.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2021-02-18T14:25:14.352339Z
Updated: 2024-09-17T03:43:54.860Z
Reserved: 2021-01-08T00:00:00
Link: CVE-2021-23340
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-02-18T15:15:14.953
Modified: 2024-11-21T05:51:32.103
Link: CVE-2021-23340
Redhat
No data.