Release date:
Updated on:
Affected Systems:
Pimcore 1.4.9-2.1.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 67615
CVE (CAN) ID: CVE-2014-2922
Pimcore is an open source Web content management platform.
In Pimcore 1.4.9-2.1.0, Newsletter of the Pimcore_Tool_Newsletter module. in php, The getObjectByToken function does not properly process the objects obtained by deserialization path names. This allows remote attackers to execute PHP code injection attacks and delete arbitrary files through the Zend_Http_Response_Stream object.
<* Source: Pedro Ribeiro
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Pimcore
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.pimcore.org/en/resources/blog/pimcore+2.2+released_b442
This article permanently updates the link address: