Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4wg4-p27p-5q2r | Pimcore Web2Print Tools Bundle "Favourite Output Channel Configuration" Missing Function Level Authorization |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pimcore
Pimcore pimcore |
|
| Vendors & Products |
Pimcore
Pimcore pimcore |
Thu, 15 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 15 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for managing "Favourite Output Channel Configurations." Testing revealed that an authenticated backend user without explicitely lacking permissions for this feature was still able to successfully invoke the endpoint and modify or retrieve these configurations. This vulnerability is fixed in 5.2.2 and 6.1.1. | |
| Title | Pimcore Web2Print Tools Bundle "Favourite Output Channel Configuration" Missing Function Level Authorization | |
| Weaknesses | CWE-284 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-15T18:26:33.948Z
Reserved: 2026-01-13T15:47:41.629Z
Link: CVE-2026-23496
Updated: 2026-01-15T18:03:59.526Z
Status : Awaiting Analysis
Published: 2026-01-15T17:16:08.747
Modified: 2026-01-16T15:55:12.257
Link: CVE-2026-23496
No data.
OpenCVE Enrichment
Updated: 2026-01-16T13:43:28Z
Github GHSA