CVE-2015-4425

Pimcore - Path Traversal

Title source: rule
STIX 2.1

Description

Directory traversal vulnerability in pimcore before build 3473 allows remote authenticated users with the "assets" permission to create or write to arbitrary files via a .. (dot dot) in the dir parameter to admin/asset/add-asset-compatibility.

Exploits (1)

exploitdb WORKING POC
by Portcullis · textwebappsxml
https://www.exploit-db.com/exploits/37609

Scores

EPSS 0.0003
EPSS Percentile 9.7%

Details

CWE
CWE-22
Status published
Products (1)
pimcore/pimcore
Published Aug 18, 2015
Tracked Since Feb 18, 2026