Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0.
@huntrdev·CWE-1049·Published 2023-09-26
Introspection is enabled on `demo.pimcore.fun`. The demo site has graphql as a feature for users, but allows users to run instropection queries, which presents a potential schema information disclosure vulnerability.