Web2Print Tools Bundle for Pimcore是Pimcore开源的一个扩展套件。 Web2Print Tools Bundle for Pimcore 5.2.2之前版本和6.1.1之前版本存在安全漏洞,该漏洞源于API端点缺少服务器端授权检查,可能导致收藏输出通道配置被修改或泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-23493 | 8.6 HIGH | Pimcore ENV Variables and Cookie Informations are exposed in http_error_log |
| CVE-2026-23495 | 4.3 MEDIUM | Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Prop |
| CVE-2026-23494 | 4.3 MEDIUM | Pimcore is Missing Function Level Authorization on "Static Routes" Listing |
No comments yet