CVE-2023-38708

MEDIUM

pimcore < 10.6.7 - Path Traversal and Arbitrary File Write via pimcore_log Parameter

Title source: llm
STIX 2.1

Description

Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exists in the `AssetController::importServerFilesAction`, which allows an attacker to overwrite or modify sensitive files by manipulating the pimcore_log parameter.This can lead to potential denial of service---key file overwrite. The impact of this vulnerability allows attackers to: overwrite or modify sensitive files, potentially leading to unauthorized access, privilege escalation, or disclosure of confidential information. This could also cause a denial of service (DoS) if critical system files are overwritten or deleted.

Scores

CVSS v3 6.3
EPSS 0.0054
EPSS Percentile 41.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
pimcore/pimcore < 10.6.7
pimcore/pimcore 0 - 10.6.7Packagist
Published Aug 04, 2023
Tracked Since Feb 18, 2026