CVE-2021-23405

Publication date

2021-07-09 12:40:15

Family

snyk

State

PUBLISHED

Description

This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the ClassificationstoreController class.