Описание
Pimcore Admin Classic Bundle provides a Backend UI for Pimcore based on the ExtJS framework. An admin who has not setup two factor authentication before is vulnerable for this attack, without need for any form of privilege, causing the application to execute arbitrary scripts/HTML content. This vulnerability has been patched in version 1.0.3.
Ссылки
- Patch
- Patch
- Vendor Advisory
- Patch
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.3 (исключая)
cpe:2.3:a:pimcore:admin_classic_bundle:*:*:*:*:*:pimcore:*:*
EPSS
Процентиль: 2%
0.00014
Низкий
5 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
github
больше 2 лет назад
Pimcore admin UI vulnerable to Cross-site Scripting in 2 factor authentication setup page
EPSS
Процентиль: 2%
0.00014
Низкий
5 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79