Show filters
144 Total Results
Displaying 21-30 of 144
Sort by:
Attacker Value
Unknown

CVE-2023-5873

Disclosure Date: October 31, 2023 (last updated November 07, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 11.1.0.
Attacker Value
Unknown

CVE-2023-5844

Disclosure Date: October 30, 2023 (last updated November 15, 2023)
Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0.
Attacker Value
Unknown

CVE-2023-5192

Disclosure Date: September 27, 2023 (last updated October 08, 2023)
Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0.
Attacker Value
Unknown

CVE-2023-42817

Disclosure Date: September 25, 2023 (last updated October 08, 2023)
Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user. The translations may be accessible by a user with comparatively lower overall access (as the translation permission cannot be scoped to certain “modules”) and a skilled attacker might be able to exploit the parsing of the translation string in the dialog box. This issue has been patched in commit `abd77392` which is included in release 1.1.2. Users are advised to update to version 1.1.2 or apply the patch manually.
Attacker Value
Unknown

CVE-2023-4453

Disclosure Date: August 21, 2023 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.8.
Attacker Value
Unknown

CVE-2023-38708

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exists in the `AssetController::importServerFilesAction`, which allows an attacker to overwrite or modify sensitive files by manipulating the pimcore_log parameter.This can lead to potential denial of service---key file overwrite. The impact of this vulnerability allows attackers to: overwrite or modify sensitive files, potentially leading to unauthorized access, privilege escalation, or disclosure of confidential information. This could also cause a denial of service (DoS) if critical system files are overwritten or deleted.
Attacker Value
Unknown

CVE-2023-4145

Disclosure Date: August 03, 2023 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2.
Attacker Value
Unknown

CVE-2023-3822

Disclosure Date: July 21, 2023 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4.
Attacker Value
Unknown

CVE-2023-3821

Disclosure Date: July 21, 2023 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.6.4.
Attacker Value
Unknown

CVE-2023-3820

Disclosure Date: July 21, 2023 (last updated October 08, 2023)
SQL Injection in GitHub repository pimcore/pimcore prior to 10.6.4.