Описание
Pimcore vulnerable to Cross Site Scripting in Documents Link Editable
Impact
An attacker can use XSS to send a malicious script to any user through Document Page Link Editable -> Advanced -> Attributes
Patches
Update to version 10.5.18 or apply this patch manually https://github.com/pimcore/pimcore/pull/14500.patch
Workarounds
Apply https://github.com/pimcore/pimcore/pull/14500.patch manually.
References
https://huntr.dev/bounties/cfa80332-e4cf-4d64-b3e5-e10298628d17/
Ссылки
- https://github.com/pimcore/pimcore/security/advisories/GHSA-97cp-8873-v2gf
- https://nvd.nist.gov/vuln/detail/CVE-2023-1115
- https://github.com/pimcore/pimcore/pull/14500.patch
- https://github.com/pimcore/pimcore/commit/c6368b7cc69a3ebf2c83de7586f492ca1f404dd3
- https://huntr.dev/bounties/cfa80332-e4cf-4d64-b3e5-e10298628d17
Пакеты
Наименование
pimcore/pimcore
composer
Затронутые версииВерсия исправления
< 10.5.18
10.5.18
Связанные уязвимости
CVSS3: 5.4
nvd
почти 3 года назад
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.