CVE-2021-23405
Last modified
CVE-2021-23405 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the ClassificationstoreController class.. EPSS estimates a 1.71% chance of exploitation in the next 30 days.
Description
This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the ClassificationstoreController class.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pimcore | Pimcore | < 10.0.7 |
References
- https://github.com/pimcore/pimcore/pull/9572Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-1316297Exploit, Third Party Advisory
- https://github.com/pimcore/pimcore/pull/9572Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-1316297Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-23405?
How severe is CVE-2021-23405?
How do I fix CVE-2021-23405?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-2340Vulnerability in the MySQL Server product of Oracle MySQL (c…2.7
- CVE-2021-23400The package nodemailer before 6.6.1 are vulnerable to HTTP H…8.8
- CVE-2021-23401This affects all versions of package Flask-User. When using …6.1
- CVE-2021-23402All versions of package record-like-deep-assign are vulnerab…9.8
- CVE-2021-23403All versions of package ts-nodash are vulnerable to Prototyp…9.8
- CVE-2021-23404This affects all versions of package sqlite-web. The SQL das…8.8
- CVE-2021-23406This affects the package pac-resolver before 5.0.0. This can…9.8
- CVE-2021-23407This affects the package elFinder.Net.Core from 0 and before…7.5
- CVE-2021-23408This affects the package com.graphhopper:graphhopper-web-bun…4.3
- CVE-2021-23409The package github.com/pires/go-proxyproto before 0.6.0 are …7.5
- CVE-2021-2341Vulnerability in the Java SE, Oracle GraalVM Enterprise Edit…3.1
- CVE-2021-23410Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2021-23405?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
