CVE-2022-39365
Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig tem
Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in Pimcore/Mail & ClassDefinition\Layout\Text is vulnerable to server-side template injection, which could lead to remote code execution. Version 10.5.9 contains a patch for this issue.
As a workaround, one may apply the patch manually.
CRITICAL · CVSS 9.8
EPSS 0.00205
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0