Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8m2r-x2m2-3wmw

Опубликовано: 28 янв. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 2.4

Описание

Duplicate Advisory: Pimcore Authenticated Stored Cross-Site Scripting (XSS) Via Search Document

Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-xr3m-6gq6-22cg. This link is maintained to preserve external references.

Original Description A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown functionality of the component Search Document. The manipulation leads to basic cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Пакеты

Наименование

pimcore/pimcore

composer
Затронутые версииВерсия исправления

>= 11.4.2

Отсутствует

5.1 Medium

CVSS4

2.4 Low

CVSS3

Дефекты

CWE-74

5.1 Medium

CVSS4

2.4 Low

CVSS3

Дефекты

CWE-74