PT-2023-20587 · Pimcore · Pimcore/Customer-Data-Framework
Mcop1
·
Published
2023-05-10
·
Updated
2023-05-31
·
CVE-2023-2629
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pimcore/customer-data-framework versions prior to 3.3.9
Description
The issue concerns improper neutralization of formula elements in a CSV file, which can lead to formula injection or CSV injection. This vulnerability affects input fields such as Firstname, Lastname, Street, Zip, and City, allowing unauthenticated attackers to execute arbitrary code via a crafted Excel file. Successful exploitation can result in client-sided command injection, code execution, or remote ex-filtration of confidential data.
Recommendations
For versions prior to 3.3.9, update to version 3.3.9 to resolve the issue.
As a temporary workaround, consider applying the patch manually from https://github.com/pimcore/customer-data-framework/commit/4e0105c3a78d20686a0c010faef27d2297b98803.patch to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pimcore/Customer-Data-Framework