First published: Fri Nov 15 2019(Updated: )
`bundles/AdminBundle/Controller/Admin/EmailController.php` in Pimcore before 6.3.0 allows script execution in the Email Log preview window because of the lack of a Content-Security-Policy header.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pimcore Pimcore | >=6.0.0<6.3.0 | |
composer/pimcore/pimcore | <6.3.0 | 6.3.0 |
>=6.0.0<6.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18982 has been classified as a medium severity vulnerability.
To fix CVE-2019-18982, upgrade to Pimcore version 6.3.0 or later.
CVE-2019-18982 can be exploited to execute malicious scripts through the Email Log preview window.
Pimcore versions prior to 6.3.0 are affected by CVE-2019-18982.
Yes, implementing a Content-Security-Policy header is necessary to mitigate CVE-2019-18982.