PT-2023-18905 · Pimcore · Pimcore
Aryaantony92
·
Published
2023-04-27
·
Updated
2024-11-19
·
CVE-2023-2332
CVSS v3.1
4.0
Medium
| Vector | AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
pimcore/pimcore version 10.5.19
Description
A stored Cross-site Scripting (XSS) vulnerability exists in the Conditions tab of Pricing Rules, specifically in the From and To fields of the Date Range section. This allows an attacker to inject malicious scripts, potentially leading to the execution of arbitrary JavaScript code in the context of the user's browser. The issue can result in stealing cookies or redirecting users to malicious sites.
Recommendations
Update to version 10.5.21 to resolve the issue.
As a temporary workaround, consider applying the patch manually from https://github.com/pimcore/pimcore/commit/a4491551967d879141a3fdf0986a9dd3d891abfe.patch to mitigate the risk.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pimcore