CVE-2014-2921 | Pimcore 1.4.9/1.5.0/2.1.0/2.2.0 Newsletter.php getObjectByToken code injection (EDB-43886)
A vulnerability was found in Pimcore 1.4.9/1.5.0/2.1.0/2.2.0. It has been classified as critical. The impacted element is the function getObjectByToken of the file Newsletter.php. Performing a manipulation results in code injection.
This vulnerability is reported as CVE-2014-2921. The attack is possible to be carried out remotely. Moreover, an exploit is present.