CVE-2021-23405
SQL injection in pimcore/pimcore
8.8
HIGH
CVSS 3.1
EPSS 0.03%
Description
This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the ClassificationstoreController class.
How to fix CVE-2021-23405
To remediate CVE-2021-23405, upgrade the affected package to a fixed version below.
- Packagist/pimcore/pimcore—upgrade to 10.0.7 or later
Is CVE-2021-23405 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 10.0.7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |