PT-2023-18905 · Pimcore · Pimcore

Aryaantony92

·

Published

2023-04-27

·

Updated

2024-11-19

·

CVE-2023-2332

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions pimcore/pimcore version 10.5.19
Description A stored Cross-site Scripting (XSS) vulnerability exists in the Conditions tab of Pricing Rules, specifically in the From and To fields of the Date Range section. This allows an attacker to inject malicious scripts, potentially leading to the execution of arbitrary JavaScript code in the context of the user's browser. The issue can result in stealing cookies or redirecting users to malicious sites.
Recommendations Update to version 10.5.21 to resolve the issue. As a temporary workaround, consider applying the patch manually from https://github.com/pimcore/pimcore/commit/a4491551967d879141a3fdf0986a9dd3d891abfe.patch to mitigate the risk.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-2332
GHSA-R7MM-JX6H-HV7M

Affected Products

Pimcore