Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Nth347

Researcher fromViettel Cyber Security
#26281of 56,329
9.8Total CVSS
Vulnerabilities · 1
PT-2022-24932
9.8
2022-10-27
Pimcore · Pimcore · CVE-2022-39365
**Name of the Vulnerable Software and Affected Versions** Pimcore versions prior to 10.5.9 **Description** The user-controlled twig templates rendering in `Pimcore/Mail` and `ClassDefinitionLayoutText` is vulnerable to server-side template injection, which could lead to remote code execution. **Recommendations** For versions prior to 10.5.9, update to version 10.5.9 to resolve the issue. As a temporary workaround for versions prior to 10.5.9, apply the patch manually.