PT-2023-28604 · Pimcore · Admin Classic Bundle

Limenet

·

Published

2023-09-25

·

Updated

2023-09-26

·

CVE-2023-42817

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pimcore admin-ui-classic-bundle versions prior to 1.1.2
Description The translation value with text including %s (from %suggest%) is parsed by sprintf() even though it's supposed to be output literally to the user. The translations may be accessible by a user with comparatively lower overall access and a skilled attacker might be able to exploit the parsing of the translation string in the dialog box.
Recommendations Update to version 1.1.2 or apply the patch manually. As a temporary workaround, consider restricting access to the translation module to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-42817
GHSA-M988-7375-7G2C

Affected Products

Admin Classic Bundle