Exploit Report

Computer Security And Bug Information

CVE-2023-28429

CVECVE-2023-28429
CVE Title
Published Date2023-03-20T15:15Z
Modified Date2023-03-23T14:08Z
CWE TypeCWE-79
CVSS 3.xCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
DescriptionPimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip field in DataObject class definition. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Users should upgrade to version 10.5.19 or, as a workaround, apply the patch manually.
References
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites.
Reference URLhttps://github.com/pimcore/pimcore/pull/14574.patch
Reference DescriptionMISC https://github.com/pimcore/pimcore/pull/14574.patch
Reference URLhttps://github.com/pimcore/pimcore/security/advisories/GHSA-rcg9-hrhx-6q69
Reference DescriptionMISC https://github.com/pimcore/pimcore/security/advisories/GHSA-rcg9-hrhx-6q69
Reference URLhttps://github.com/pimcore/pimcore/pull/14574
Reference DescriptionMISC https://github.com/pimcore/pimcore/pull/14574
TagsPatch
Sources NIST MITRE

This site's data is aggregated programmatically and provided "as is" without any representations or warranties, express or implied. Exploit.report is not affiliated with the The MITRE Corporation, U.S. Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), or US government in any way. CVE and the CVE logo are registered trademarks of The MITRE Corporation

© 2022 Exploit.Report | Data | Contact | Privacy Policy | Articles