{"id":"CVE-2019-16318","aliases":["GHSA-cxj7-4jpj-2q38","SNYK-PHP-PIMCOREPIMCORE-451598"],"url":"https://o3.security/vulnerability/CVE-2019-16318","summary":"Pimcore Unrestricted Upload of File with Dangerous Type","details":"In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character filename, as demonstrated by the failure of automatic renaming of .php to .php.txt for long filenames, a different vulnerability than CVE-2019-10867 and CVE-2019-16317.","published":"2019-09-14T18:15:11.260Z","modified":"2026-08-07T15:18:06.037852Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"pimcore/pimcore","fixedVersion":"5.7.1"}],"fix":{"url":"https://github.com/pimcore/pimcore/commit/732f1647cc6e0a29b5b1f5d904b4d726b5e9455f","label":"pimcore/pimcore@732f164"},"references":[{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-451598"},{"type":"FIX","url":"https://github.com/pimcore/pimcore/commit/732f1647cc6e0a29b5b1f5d904b4d726b5e9455f"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:18:06.037852Z"}}