Security Advisory

CVE-2021-23405

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-07-09 12:40:15
Last updated 2024-09-16 19:04:05
Assigner snyk
CVSS score 8.3
State PUBLISHED

Description

This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the ClassificationstoreController class.