Unrestricted Website Settings Modification in Pimcore (CVE-2021-12345)

Unrestricted Website Settings Modification in Pimcore (CVE-2021-12345)

CVE-2020-26246 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create website settings without having the appropriate permissions.

Learn more about our Web App Pen Testing.