PT-2023-31044 · Pimcore · Pimcore/Customer-Data-Framework

Vesh3

·

Published

2023-11-30

·

Updated

2023-12-05

·

CVE-2023-49076

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pimcore Customer-data-framework versions prior to 4.0.5
Description The issue allows an attacker to create new customers due to the lack of tokens or headers to prevent CSRF attacks. This can be exploited to manage customer data within Pimcore.
Recommendations For versions prior to 4.0.5, update to version 4.0.5 to resolve the issue. As a temporary workaround, consider implementing additional security measures to prevent CSRF attacks, such as validating requests through other means.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2023-49076
GHSA-XX63-4JR8-9GHC

Affected Products

Pimcore/Customer-Data-Framework