PT-2023-28604 · Pimcore · Admin Classic Bundle
Limenet
·
Published
2023-09-25
·
Updated
2023-09-26
·
CVE-2023-42817
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pimcore admin-ui-classic-bundle versions prior to 1.1.2
Description
The translation value with text including
%s (from %suggest%) is parsed by sprintf() even though it's supposed to be output literally to the user. The translations may be accessible by a user with comparatively lower overall access and a skilled attacker might be able to exploit the parsing of the translation string in the dialog box.Recommendations
Update to version 1.1.2 or apply the patch manually. As a temporary workaround, consider restricting access to the translation module to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Admin Classic Bundle