Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create website settings without having the appropriate permissions.
References
Link | Resource |
---|---|
https://github.com/pimcore/pimcore/security/advisories/GHSA-7p8p-4253-3mg6 | Third Party Advisory |
https://github.com/pimcore/pimcore/pull/7618 | Patch Third Party Advisory |
Configurations
Information
Published : 2020-12-02 17:15
Updated : 2020-12-03 07:41
NVD link : CVE-2020-26246
Mitre link : CVE-2020-26246
JSON object : View
CWE
CWE-281
Improper Preservation of Permissions
Products Affected
pimcore
- pimcore