CVE-2015-4425: Pimcore

Medium severity, CVSS 4.9. EPSS: 3.8% chance of exploitation in the next 30 days.

Directory traversal vulnerability in pimcore before build 3473 allows remote authenticated users with the "assets" permission to create or write to arbitrary files via a .. (dot dot) in the dir parameter to admin/asset/add-asset-compatibility.

Affected products

  • Pimcore Pimcore: affected versions not specified

Published 2015-08-18. Last modified 2026-06-17.