Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m988-7375-7g2c

Опубликовано: 25 сент. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

pimcore/admin-ui-classic-bundle Cross-site Scripting vulnerability in Translations

Impact

The translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user.

The translations may be accessible by a user with comparatively lower overall access (as the translation permission cannot be scoped to certain “modules”) and a skilled attacker might be able to exploit the parsing of the translation string in the dialog box.

Patches

https://github.com/pimcore/admin-ui-classic-bundle/commit/abd7739298f974319e3cac3fd4fcd7f995b63e4c.patch

Workarounds

Update to version 1.1.2 or apply this patches manually https://github.com/pimcore/admin-ui-classic-bundle/commit/abd7739298f974319e3cac3fd4fcd7f995b63e4c.patch

Пакеты

Наименование

pimcore/admin-ui-classic-bundle

composer
Затронутые версииВерсия исправления

< 1.1.2

1.1.2

EPSS

Процентиль: 0%
0.00004
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user. The translations may be accessible by a user with comparatively lower overall access (as the translation permission cannot be scoped to certain “modules”) and a skilled attacker might be able to exploit the parsing of the translation string in the dialog box. This issue has been patched in commit `abd77392` which is included in release 1.1.2. Users are advised to update to version 1.1.2 or apply the patch manually.

EPSS

Процентиль: 0%
0.00004
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79