• caglararli@hotmail.com
  • 05386281520

CVE-2024-23646 | Pimcore admin-ui-classic-bundle up to 1.3.1 ZIP File selectedIds sql injection

Çağlar Arlı      -    16 Views

CVE-2024-23646 | Pimcore admin-ui-classic-bundle up to 1.3.1 ZIP File selectedIds sql injection

A vulnerability, which was classified as critical, has been found in Pimcore admin-ui-classic-bundle up to 1.3.1. This issue affects some unknown processing of the component ZIP File Handler. The manipulation of the argument selectedIds leads to sql injection. The identification of this vulnerability is CVE-2024-23646. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected component.