GHSA-g7pj-3v97-3vxp
Dashboard / Vulnerabilities / GHSA-g7pj-3v97-3vxp
Summary: Pimcore Vulnerable to PHP Object Injection Attacks
Details: The `getObjectByToken` function in `Newsletter.php` in the `Pimcore_Tool_Newsletter` module in pimcore 1.4.9 through 2.0.0 does not properly handle an object obtained by unserializing Lucene search data, which allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via vectors involving a `Zend_Pdf_ElementFactory_Proxy` object and a pathname with a trailing `\0` character.
References: https://nvd.nist.gov/vuln/detail/CVE-2014-2921, https://github.com/pimcore/pimcore/commit/3cb2683e669b5644f180d362cfa9614c09bef280, https://github.com/pedrib/PoC/blob/caa03645e256a8b50f1101c983d39586ebc467ee/advisories/pimcore-2.1.0.txt, https://github.com/pedrib/PoC/blob/master/pimcore-2.1.0.txt, https://github.com/pimcore/pimcore, http://openwall.com/lists/oss-security/2014/04/21/1, http://www.pimcore.org/en/resources/blog/pimcore+2.2+released_b442
Affected packages
Package
Name: pimcore/pimcore
Purl: pkg:composer/pimcore/pimcore
Affected ranges
Type: ECOSYSTEM
Events:
