First published: Fri Dec 10 2021(Updated: )
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Pimcore Pimcore | <10.2.6 | |
<10.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-4081 is classified as a moderate severity vulnerability due to the potential for Cross-site Scripting attacks.
To fix CVE-2021-4081, update your Pimcore installation to version 10.2.6 or later.
CVE-2021-4081 is an Improper Neutralization of Input During Web Page Generation vulnerability, commonly known as Cross-site Scripting (XSS).
CVE-2021-4081 affects all versions of Pimcore prior to 10.2.6.
Yes, user input is at risk as CVE-2021-4081 could allow attackers to execute malicious scripts in the context of user sessions.