PT-2022-21361 · Pimcore+2 · Pimcore+1

Kingjia90

·

Published

2022-09-21

·

Updated

2022-09-23

·

CVE-2022-3255

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software name is mentioned, but based on the information provided, the affected software is likely a web application. Since the affected versions are not explicitly mentioned, the output will be: Web application (affected versions not specified)
Description If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user. The attacker can perform any action within the application that the user can perform, view any information that the user is able to view, modify any information that the user is able to modify, and initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3255
GHSA-WQR6-57QM-HHR5

Affected Products

Pimcore
Pimcore/Pimcore