CVE-2023-2629
MEDIUM
Published 2023-05-10T00:00:00.000Z
Actions:
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2023-2629. We'll provide specific mitigation strategies based on your environment and risk profile.
CVSS Score
V3.0
5.0
/10
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:L
Base Score Metrics
Exploitability: N/A
Impact: N/A
EPSS Score
v2025.03.14
0.000
probability
of exploitation in the wild
There is a 0.0% chance that this vulnerability will be exploited in the wild within the next 30 days.
Updated: 2025-06-25
Exploit Probability
Percentile: 0.000
Higher than 0.0% of all CVEs
Attack Vector Metrics
Impact Metrics
Description
Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9.
Available Exploits
No exploits available for this CVE.
Related News
No news articles found for this CVE.
Affected Products
Affected Versions:
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
✓ GitHub Reviewed
HIGH
Embedding untrusted input inside CSV files leads to Formula Injection/CSV Injection
GHSA-mq3x-qgwx-3rfwAdvisory Details
### Impact
The pimcore application is vulnerable to Formula Injection/CSV Injection via the Firstname, Lastname, Street, Zip & City input fields. These vulnerabilities allow unauthenticated attackers to execute arbitrary code via a crafted excel file.
Successful exploitation can lead to impacts such as client-sided command injection, code execution, or remote ex-filtration of contained confidential data.
### Patches
Update to version 3.3.9 or apply this patch manually https://github.com/pimcore/customer-data-framework/commit/4e0105c3a78d20686a0c010faef27d2297b98803.patch
### Workarounds
Apply patch https://github.com/pimcore/customer-data-framework/commit/4e0105c3a78d20686a0c010faef27d2297b98803.patch manually.
### References
https://huntr.dev/bounties/821ff465-4754-42d1-9376-813c17f16a01/
Affected Packages
Packagist
pimcore/customer-management-framework-bundle
ECOSYSTEM:
≥0
<3.3.9
CVSS Scoring
CVSS Score
7.5
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References
Advisory provided by GitHub Security Advisory Database. Published: May 11, 2023, Modified: May 17, 2023
References
Published: 2023-05-10T00:00:00.000Z
Last Modified: 2025-01-27T19:40:22.120Z
Copied to clipboard!