CVE-2023-38708: Pimcore Path Traversal Vulnerability in AssetController:importServerFilesAction
6.3
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.00124%
CWE
Published
8/3/2023
Updated
11/11/2023
KEV Status
No
Technology
PHP
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| pimcore/pimcore | composer | < 10.6.7 | 10.6.7 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability stems from the unpatched version of importServerFilesAction which handled user-supplied file paths without proper sanitization. The commit diff shows the vulnerability was addressed by adding realpath() checks and path containment validation. The function's direct use of unsanitized user input ($request->get('files')) to build filesystem paths makes it the clear entry point for the path traversal attack. The CWE-22 mapping and patch location confirm this assessment.