First published: Wed Aug 18 2021(Updated: )
Pimcore is an open source data & experience management platform. Prior to version 10.1.1, Data Object CSV import allows formular injection. The problem is patched in 10.1.1. Aside from upgrading, one may apply the patch manually as a workaround.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pimcore E-commerce Framework | <10.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37702 has been classified as a medium severity vulnerability due to its potential for formular injection during data object CSV import.
To fix CVE-2021-37702, upgrade to Pimcore version 10.1.1 or apply the provided patch manually.
The impact of CVE-2021-37702 allows attackers to perform formular injection through the CSV import feature, which could compromise data integrity.
CVE-2021-37702 affects all versions of Pimcore prior to version 10.1.1.
Yes, you can apply a manual patch as a workaround for CVE-2021-37702 if upgrading is not immediately possible.