QID 995946
Date Published: 2023-11-16
QID 995946: PHP (Composer) Security Update for pimcore/admin-ui-classic-bundle (GHSA-c8hj-w239-5gvf)
Full Path Disclosure (FPD) vulnerabilities enable the attacker to see the path to the webroot/file. e.g.: /home/omg/htdocs/file/. Certain vulnerabilities, such as using the load_file() (within a SQL Injection) query to view the page source, require the attacker to have the full path to the file they wish to view.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-c8hj-w239-5gvf for updates and patch information.
Vendor References
- GHSA-c8hj-w239-5gvf -
github.com/advisories/GHSA-c8hj-w239-5gvf
CVEs related to QID 995946
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c8hj-w239-5gvf | pimcore/admin-ui-classic-bundle |
|