← back
CVE-2019-10867

CVE-2019-10867

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 69%
from disclosure to weapon26 days
Published on NVDApr 4
1st PoC+26d
metasploitMar 11
exploitation probability
69%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to bundles/AdminBundle/Controller/Admin/DataObject/ClassController.php.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.