CVE-2019-10867

HIGH

pimcore < 5.7.1 - Authenticated Remote Code Execution via Unserialize in Bulk-Commit Endpoint

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2019-10867. PoCs published by Metasploit, Daniele Scanu, Fabio Cogno, including Metasploit module exploits/multi/http/pimcore_unserialize_rce.

AI-analyzed exploit summary This Metasploit module exploits a PHP unserialize vulnerability in Pimcore before 5.7.1, allowing authenticated users with 'classes' permission to execute arbitrary code via the 'bulk-commit' method in ClassController.php.

Description

An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to bundles/AdminBundle/Controller/Admin/DataObject/ClassController.php.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/46783

This Metasploit module exploits a PHP unserialize vulnerability in Pimcore before 5.7.1, allowing authenticated users with 'classes' permission to execute arbitrary code via the 'bulk-commit' method in ClassController.php.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Pimcore 4.0.0-4.6.5, 5.4.0-5.4.4, 5.5.1-5.5.4, 5.6.0-5.6.6
Auth required
Prerequisites: Valid credentials with 'classes' permission · Access to the Pimcore admin interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Daniele Scanu, Fabio Cogno · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/pimcore_unserialize_rce.rb

This Metasploit module exploits a PHP unserialize vulnerability in Pimcore (CVE-2019-10867) to achieve remote code execution. It authenticates, uploads a malicious JSON payload, and triggers deserialization via the 'bulk-commit' method.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Pimcore 4.0.0-4.6.5, 5.0.0-5.6.6
Auth required
Prerequisites: Valid credentials with 'classes' permission · Access to Pimcore admin interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-173998
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/152667/Pimcore-Unserialize-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/46783/

Scores

CVSS v3 8.8
EPSS 0.5273
EPSS Percentile 98.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (2)
pimcore/pimcore < 5.7.1
pimcore/pimcore 0 - 5.7.1Packagist
Published Apr 04, 2019
Tracked Since Feb 18, 2026