CVE-2023-4145
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to inject malicious scripts into the customer management framework, which can then be executed in the browsers of users who access the affected application. It requires the attacker to have the ability to input data into the system, making it particularly dangerous if user-generated content is not properly sanitized.
Technical Description
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Aug 3, 2023
over 2 years ago
Last Modified
Mar 6, 2026
about 1 month ago
Vendor
pimcore
Product
customer management framework
Related Vulnerabilities
This vulnerability allows an attacker to potentially access user passwords stored in a recoverable format within the customer management framework, which could lead to unauthorized account access. It affects versions prior to 3.3.10, meaning systems running older versions are at risk if they haven't been updated.
This vulnerability allows an attacker to manipulate database queries, potentially gaining unauthorized access to sensitive data or executing harmful commands. It affects versions 6.8.0 and earlier of the Pimcore AdminBundle, and users should upgrade to version 6.9.4 or later to protect against this issue.