Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://huntr.dev/bounties/96506857-06bc-4c84-88b7-4f397715bcf6 | exploit third party advisory patch |
https://github.com/pimcore/pimcore/commit/35d1853baf64d6a1d90fd8803e52439da53a3911 | third party advisory patch |