PT-2025-1723 · Pimcore · Pimcore

Maeitsec

·

Published

2025-01-28

·

Updated

2025-11-04

·

CVE-2024-11954

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pimcore version 11.4.2
Description A problematic issue was found in the Search Document component, leading to basic cross site scripting. The manipulation can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations Pimcore version 11.4.2: Update to a version that fixes the issue in the Search Document component to prevent basic cross site scripting.

Exploit

Fix

Special Elements Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-11954
GHSA-8M2R-X2M2-3WMW
GHSA-XR3M-6GQ6-22CG

Affected Products

Pimcore