First published: Fri Jul 09 2021(Updated: )
This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the ClassificationstoreController class.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Pimcore E-commerce Framework | <10.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-23405 is classified as medium due to potential unauthorized access risks.
To fix CVE-2021-23405, you should upgrade to pimcore/pimcore version 10.0.7 or later.
CVE-2021-23405 affects Pimcore versions prior to 10.0.7.
The root cause of CVE-2021-23405 is the lack of validation on the storeId parameter in specific methods of the ClassificationstoreController.
As of now, there are no publicly disclosed exploits for CVE-2021-23405, but it poses a risk if not mitigated.