SCA: security update for pimcore/pimcore (GHSA-g2mc-fqqc-hxg3)

high Tenable Cloud Security Plugin ID 414794

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Pimcore is an open source data and experience management platform. Versions of Pimcore prior to 10.5.18
are vulnerable to path traversal. The impact of this path traversal and arbitrary extension is limited to
creation of arbitrary files and appending data to existing files. When combined with the SQL Injection,
the exported data `RESTRICTED DIFFUSION 9 / 9` can be controlled and a webshell can be uploaded. Attackers
can use that to execute arbitrary PHP code on the server with the permissions of the webserver. Users may
upgrade to version 10.5.18 to receive a patch or, as a workaround, apply the patch manually.
(CVE-2023-30855)

See Also

https://github.com/advisories/GHSA-g2mc-fqqc-hxg3

Plugin Details

Severity: High

ID: 414794

Version: Revision 1.12

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2023-30855

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/2/2023

Vulnerability Publication Date: 5/2/2023

Reference Information

CVE: CVE-2023-30855

cwe: CWE-22