PT-2025-1723 · Pimcore · Pimcore
Maeitsec
·
Published
2025-01-28
·
Updated
2025-11-04
·
CVE-2024-11954
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Pimcore version 11.4.2
Description
A problematic issue was found in the Search Document component, leading to basic cross site scripting. The manipulation can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations
Pimcore version 11.4.2: Update to a version that fixes the issue in the Search Document component to prevent basic cross site scripting.
Exploit
Fix
Special Elements Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pimcore