CVE-2014-2921
Pimcore Vulnerable to PHP Object Injection Attacks
EPSS 7.3%
Description
The `getObjectByToken` function in `Newsletter.php` in the `Pimcore_Tool_Newsletter` module in pimcore 1.4.9 through 2.0.0 does not properly handle an object obtained by unserializing Lucene search data, which allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via vectors involving a `Zend_Pdf_ElementFactory_Proxy` object and a pathname with a trailing `\0` character.
How to fix CVE-2014-2921
To remediate CVE-2014-2921, upgrade the affected package to a fixed version below.
- Packagist/pimcore/pimcore—upgrade to 2.2.0 or later
Is CVE-2014-2921 being exploited?
Moderate — EPSS is 7.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 1.4.9, < 2.2.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P |