Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| akeneo/pim-community-dev(Packagist) | 1.4 | 1.4.28 | N/A |
| akeneo/pim-community-dev(Packagist) | 1.5 | 1.5.15 | N/A |
| akeneo/pim-community-dev(Packagist) | 1.6 | 1.6.6 | N/A |
CVSS Metrics