CVE-2021-23340

HIGH

pimcore <6.8.8 - Local File Inclusion

Title source: llm
STIX 2.1

Description

This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAction function of the CustomReportController class (bundles/AdminBundle/Controller/Reports/CustomReportController.php). An authenticated user can reach this function with a GET request at the following endpoint: /admin/reports/custom-report/download-csv?exportFile=&91;filename]. Since exportFile variable is not sanitized, an attacker can exploit a local file inclusion vulnerability.

References (3)

Core 3

Scores

CVSS v3 7.1
EPSS 0.0132
EPSS Percentile 67.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Details

CWE
CWE-22
Status published
Products (2)
pimcore/pimcore < 6.8.8
pimcore/pimcore 0 - 6.8.8Packagist
Published Feb 18, 2021
Tracked Since Feb 18, 2026