PT-2021-22423 · Pimcore · Pimcore

Brusch

·

Published

2021-09-01

·

Updated

2021-09-09

·

CVE-2021-39166

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pimcore versions prior to 10.1.2
Description The issue concerns the Pimcore open source data & experience management platform. In this platform, text-values were not properly escaped before being printed in the version preview. This allowed cross-site scripting (XSS) attacks by authenticated users who had access to the resources.
Recommendations For Pimcore versions prior to 10.1.2, update to version 10.1.2 to resolve the issue. As a temporary workaround, consider restricting access to the version preview feature to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-39166
GHSA-W6J8-JC36-X5Q9

Affected Products

Pimcore