Логотип exploitDog
bind:CVE-2023-28429
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-28429

Количество 2

Количество 2

nvd логотип

CVE-2023-28429

почти 3 года назад

Pimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip field in DataObject class definition. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Users should upgrade to version 10.5.19 or, as a workaround, apply the patch manually.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-rcg9-hrhx-6q69

почти 3 года назад

Pimcore has Cross-site Scripting vulnerability in DataObject tooltip field

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-28429

Pimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip field in DataObject class definition. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Users should upgrade to version 10.5.19 or, as a workaround, apply the patch manually.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-rcg9-hrhx-6q69

Pimcore has Cross-site Scripting vulnerability in DataObject tooltip field

CVSS3: 6.1
0%
Низкий
почти 3 года назад

Уязвимостей на страницу