← voltar
CVE-2024-32871highCWE-770

Pimcore Vulnerable to Flooding Server with Thumbnail files

21Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 7.5epss 0.8%
probabilidade de exploração
0.8%top 48% das CVEs
exploração observada
nãonenhuma fonte reporta
Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. By changing the file extension or scaling factor of the requested thumbnail, attackers can create files that are much larger in file size than the original. This vulnerability is fixed in 11.2.4.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Produtos afetados
pimcore · pimcore