Description
The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Users should upgrade to version 1.2.0 to receive a patch or, as a workaround, apply the patch manually.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jfxw-6c5v-c42f | Pimcore Admin Classic Bundle Cross-site Scripting (XSS) in PDF previews |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-05T18:54:28.906Z
Reserved: 2023-10-25T14:30:33.750Z
Link: CVE-2023-46722
Updated: 2024-08-02T20:53:21.608Z
Status : Modified
Published: 2023-10-31T16:15:10.157
Modified: 2024-11-21T08:29:09.103
Link: CVE-2023-46722
No data.
OpenCVE Enrichment
No data.
Github GHSA