Pimcore是Pimcore公司开源的一套开源的用于创建和管理Web应用程序的Web内容管理平台。该平台集成了Web内容管理、电子商务框架和产品信息管理等应用。 Pimcore 11.5.17之前版本和12.3.7之前版本存在授权问题漏洞,该漏洞源于WebDAV资产端点缺少身份验证插件,且在执行资产操作前未检查用户权限,可能导致未经授权的资产删除、移动或覆盖。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-44739 | 8.7 HIGH | Pimcore: SQL Injection in Custom Reports Column Configuration |
| CVE-2026-45162 | 8.0 HIGH | Pimcore: Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restrict |
| CVE-2026-45703 | 6.4 MEDIUM | Pimcore: WordExport Authorization Bypass for Unauthorized Document Export |
| CVE-2026-45704 | Pimcore: CustomReports Share Bypass |
No comments yet