Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2v88-qq7x-xq5f

Опубликовано: 01 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Improper Encoding or Escaping of Output in Asset Metadata Component

Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets. There is a patch for this issue in Pimcore version 10.1.2. As a workaround, users may apply the patch manually.

Пакеты

Наименование

pimcore/pimcore

composer
Затронутые версииВерсия исправления

< 10.1.1

10.1.2

EPSS

Процентиль: 5%
0.0002
Низкий

8 High

CVSS3

Дефекты

CWE-116
CWE-79

Связанные уязвимости

CVSS3: 8
nvd
больше 4 лет назад

Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets. There is a patch for this issue in Pimcore version 10.1.2. As a workaround, users may apply the patch manually.

EPSS

Процентиль: 5%
0.0002
Низкий

8 High

CVSS3

Дефекты

CWE-116
CWE-79