PT-2018-12313 · Pimcore · Pimcore

N. Rai-Ngoen

+1

·

Published

2018-08-24

·

Updated

2022-05-14

·

CVE-2018-14059

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pimcore (affected versions not specified)
Description The issue allows for XSS attacks through various functions, including Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14059
GHSA-276R-24XQ-HWG8

Affected Products

Pimcore