3/2/2023
2/8/2024
CVE-2023-23937: Missing file upload type validation in pimcore/pimcore
First published: Fri Feb 03 2023(Updated: )
Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce.
The upload functionality for updating user profile does not properly validate the file content-type, allowing any authenticated user to bypass this security check by adding a valid signature (p.e. GIF89) and sending any invalid content-type. This could allow an authenticated attacker to upload HTML files with JS content that will be executed in the context of the domain. This issue has been patched in version 10.5.16.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|
Pimcore Pimcore | <10.5.16 | |
Never miss a vulnerability like this again
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Frequently Asked Questions
What is CVE-2023-23937 vulnerability?
The upload functionality for updating user profile does not properly validate the file content-type in Pimcore, allowing authenticated users to bypass security checks.
How severe is CVE-2023-23937?
CVE-2023-23937 has a severity keyword of 'high' with a CVSS score of 5.4.
What software versions are affected by CVE-2023-23937?
Pimcore versions up to 10.5.16 are affected by CVE-2023-23937.
- collector/nvd-index
- agent/type
- agent/references
- agent/softwarecombine
- agent/remedy
- collector/mitre-cve
- source/MITRE
- agent/weakness
- agent/last-modified-date
- agent/author
- agent/severity
- agent/title
- agent/tags
- agent/first-publish-date
- agent/event
- agent/description
- vendor/pimcore
- canonical/pimcore pimcore
Contact
SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.coBy using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203