N. Rai-Ngoen

4 exploits Active since Aug 2018
CVE-2018-14058 EXPLOITDB MEDIUM text WRITEUP
pimcore < 5.3.0 - SQL Injection via REST Web Service API
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
CVSS 6.5
CVE-2018-14057 EXPLOITDB HIGH text WRITEUP
pimcore < 5.3.0 - Cross-Site Request Forgery via Missing CSRF Token Validation
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function.
CVSS 8.8
CVE-2018-14058 METASPLOIT MEDIUM ruby WORKING POC
pimcore < 5.3.0 - SQL Injection via REST Web Service API
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
CVSS 6.5
CVE-2018-14059 EXPLOITDB MEDIUM text WRITEUP
pimcore < 5.2.3 and >=0 < 5.3.0 - Cross-Site Scripting via Multiple Input Fields
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions.
CVSS 5.4