Vulnerabilities > Pimcore > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-08-17 CVE-2018-14057 Cross-Site Request Forgery (CSRF) vulnerability in Pimcore
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function.
network
pimcore CWE-352
6.8
2015-08-18 CVE-2015-4425 Path Traversal vulnerability in Pimcore
Directory traversal vulnerability in pimcore before build 3473 allows remote authenticated users with the "assets" permission to create or write to arbitrary files via a ..
network
pimcore CWE-22
4.9
2014-04-21 CVE-2014-2922 Improper Input Validation vulnerability in Pimcore 1.4.9/1.5.0/2.1.0
The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.1.0 does not properly handle an object obtained by unserializing a pathname, which allows remote attackers to conduct PHP object injection attacks and delete arbitrary files via vectors involving a Zend_Http_Response_Stream object.
network
low complexity
pimcore CWE-20
6.4