Vulnerability CVE-2023-28106


Published: 2023-03-16

Description:
Pimcore is an open source data and experience management platform. Prior to version 10.5.19, an attacker can use cross-site scripting to send a malicious script to an unsuspecting user. Users may upgrade to version 10.5.19 to receive a patch or, as a workaround, apply the patch manually.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://github.com/pimcore/pimcore/commit/c59d0bf1d03a5037b586fe06230694fa3818dbf2
https://github.com/pimcore/pimcore/pull/14669.patch
https://huntr.dev/bounties/fa77d780-9b23-404b-8c44-12108881d11a
https://github.com/pimcore/pimcore/security/advisories/GHSA-x5j3-mq9g-8jc8

Copyright 2024, cxsecurity.com

 

Back to Top