Loading HuntDB...

Vulnerabilities

CVE-2023-2340

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

Published Apr 27, 2023

CVE-2023-2343

MEDIUM

Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.

Published Apr 27, 2023

CVE-2023-2338

HIGH

SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.21.

Published Apr 27, 2023

CVE-2023-2323

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

Published Apr 27, 2023

CVE-2023-2328

MEDIUM

Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.

Published Apr 27, 2023

CVE-2023-2341

HIGH

Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.

Published Apr 27, 2023

CVE-2023-2322

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

Published Apr 27, 2023

CVE-2023-2336

MEDIUM

Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21.

Published Apr 27, 2023

CVE-2023-2339

MEDIUM

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.

Published Apr 27, 2023

CVE-2023-28850

MEDIUM

Pimcore Perspective Editor provides an editor for Pimcore that allows users to add/remove/edit custom views and perspectives. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Version 1.5.1 has a patch. As a workaround, one may apply the patch manually.

Published Apr 03, 2023

CVE-2023-1704

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.20.

Published Mar 29, 2023

CVE-2023-1702

MEDIUM

Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.

Published Mar 29, 2023

CVE-2023-1703

MEDIUM

Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.

Published Mar 29, 2023

CVE-2023-1701

MEDIUM

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.20.

Published Mar 29, 2023

CVE-2023-28438

MEDIUM

Pimcore is an open source data and experience management platform. Prior to version 10.5.19, since a user with 'report' permission can already write arbitrary SQL queries and given the fact that this endpoint is using the GET method (no CSRF protection), an attacker can inject an arbitrary query by manipulating a user to click on a link. Users should upgrade to version 10.5.19 to receive a patch or, as a workaround, may apply the patch manually.

Published Mar 22, 2023

CVE-2023-1578

MEDIUM

SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.

Published Mar 22, 2023

CVE-2023-28429

MEDIUM

Pimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip field in DataObject class definition. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Users should upgrade to version 10.5.19 or, as a workaround, apply the patch manually.

Published Mar 20, 2023

CVE-2023-1517

MEDIUM

Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.19.

Published Mar 20, 2023

CVE-2023-1515

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.19.

Published Mar 20, 2023

CVE-2023-28108

HIGH

Pimcore is an open source data and experience management platform. Prior to version 10.5.19, quoting is not done properly in UUID DAO model. There is the theoretical possibility to inject custom SQL if the developer is using this methods with input data and not doing proper input validation in advance and so relies on the auto-quoting being done by the DAO class. Users should update to version 10.5.19 to receive a patch or, as a workaround, apply the patch manually.

Published Mar 16, 2023

CVE-2023-28106

MEDIUM

Pimcore is an open source data and experience management platform. Prior to version 10.5.19, an attacker can use cross-site scripting to send a malicious script to an unsuspecting user. Users may upgrade to version 10.5.19 to receive a patch or, as a workaround, apply the patch manually.

Published Mar 16, 2023

CVE-2023-1429

MEDIUM

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.19.

Published Mar 16, 2023

CVE-2023-1312

MEDIUM

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.19.

Published Mar 10, 2023

CVE-2023-1286

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.19.

Published Mar 09, 2023

CVE-2023-1117

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.

Published Mar 01, 2023

CVE-2023-1116

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.

Published Mar 01, 2023

CVE-2023-1115

HIGH

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.

Published Mar 01, 2023

CVE-2023-1067

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.

Published Feb 27, 2023

CVE-2023-0827

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 1.5.17.

Published Feb 14, 2023

CVE-2023-23937

HIGH

Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. The upload functionality for updating user profile does not properly validate the file content-type, allowing any authenticated user to bypass this security check by adding a valid signature (p.e. GIF89) and sending any invalid content-type. This could allow an authenticated attacker to upload HTML files with JS content that will be executed in the context of the domain. This issue has been patched in version 10.5.16.

Published Feb 03, 2023

CVE-2023-0323

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.14.

Published Jan 16, 2023

CVE-2022-39365

CRITICAL

Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout\Text` is vulnerable to server-side template injection, which could lead to remote code execution. Version 10.5.9 contains a patch for this issue. As a workaround, one may apply the patch manually.

Published Oct 27, 2022

CVE-2022-3255

MEDIUM

If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user. Amongst other things, the attacker can: Perform any action within the application that the user can perform. View any information that the user is able to view. Modify any information that the user is able to modify. Initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user.

Published Sep 21, 2022

CVE-2022-3211

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.6.

Published Sep 15, 2022

CVE-2022-2796

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.4.

Published Aug 23, 2022

CVE-2022-31092

HIGH

Pimcore is an Open Source Data & Experience Management Platform. Pimcore offers developers listing classes to make querying data easier. This listing classes also allow to order or group the results based on one or more columns which should be quoted by default. The actual issue is that quoting is not done properly in both cases, so there's the theoretical possibility to inject custom SQL if the developer is using this methods with input data and not doing proper input validation in advance and so relies on the auto-quoting being done by the listing classes. This issue has been resolved in version 10.4.4. Users are advised to upgrade or to apple the patch manually. There are no known workarounds for this issue.

Published Jun 27, 2022

CVE-2022-1429

HIGH

SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6. This vulnerability is capable of steal the data

Published Apr 22, 2022

CVE-2022-1351

MEDIUM

Stored XSS in Tooltip in GitHub repository pimcore/pimcore prior to 10.4.

Published Apr 14, 2022

CVE-2022-1339

HIGH

SQL injection in ElementController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data

Published Apr 13, 2022

CVE-2022-1219

HIGH

SQL injection in RecyclebinController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data

Published Apr 08, 2022

CVE-2022-0955

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/data-hub prior to 1.2.4.

Published Mar 24, 2022

CVE-2022-0705

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

Published Mar 16, 2022

CVE-2022-0704

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

Published Mar 16, 2022

CVE-2022-0911

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

Published Mar 16, 2022

CVE-2022-0893

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

Published Mar 15, 2022

CVE-2022-0894

HIGH

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

Published Mar 15, 2022

CVE-2022-0832

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.

Published Mar 04, 2022

CVE-2022-0831

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.

Published Mar 04, 2022

CVE-2022-0665

MEDIUM

Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2.

Published Feb 22, 2022

CVE-2022-0565

HIGH

Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1.

Published Feb 12, 2022