Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w6j8-jc36-x5q9

Опубликовано: 01 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Improper Neutralization of Text-Values in Object Version Preview

Text-values were not properly escaped before printed in the version preview. This allowed XSS by authenticated users with access to the resources.

Пакеты

Наименование

pimcore/pimcore

composer
Затронутые версииВерсия исправления

< 10.1.1

10.1.2

EPSS

Процентиль: 2%
0.00015
Низкий

8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8
nvd
больше 4 лет назад

Pimcore is an open source data & experience management platform. Prior to version 10.1.2, text-values were not properly escaped before printed in the version preview. This allowed XSS by authenticated users with access to the resources. This issue is patched in Pimcore version 10.1.2.

EPSS

Процентиль: 2%
0.00015
Низкий

8 High

CVSS3

Дефекты

CWE-79