Логотип exploitDog
bind:CVE-2024-11956
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-11956

Количество 2

Количество 2

nvd логотип

CVE-2024-11956

около 1 года назад

A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unknown functionality of the file /admin/customermanagementframework/customers/list. The manipulation of the argument filterDefinition/filter leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-q53r-9hh9-w277

около 1 года назад

pimcore/customer-data-framework vulnerable to SQL Injection

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-11956

A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unknown functionality of the file /admin/customermanagementframework/customers/list. The manipulation of the argument filterDefinition/filter leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 4.7
0%
Низкий
около 1 года назад
github логотип
GHSA-q53r-9hh9-w277

pimcore/customer-data-framework vulnerable to SQL Injection

CVSS3: 7.2
0%
Низкий
около 1 года назад

Уязвимостей на страницу