CVE-2014-2921

high
Published 2014-04-21 · Modified 2025-04-13
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Pimcore Vulnerable to PHP Object Injection Attacks

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.pimcore.org/en/resources/blog/pimcore+2.2+released_b442

Package impact

EcosystemPackageVulnerableFixed
php Packagistpimcore/pimcore>=1.4.9,<2.2.02.2.0

Application impact

VendorProductVersionsFixed
pimcorepimcore1.4.9
pimcorepimcore1.5.0
pimcorepimcore2.1.0
pimcorepimcore2.2.0

References

CWEs

CWE-94

Verify integrity in audit chain (admin only). AS-IS.