First published: Sat Feb 12 2022(Updated: )
Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1.
Credit: security@huntr.dev security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
composer/pimcore/pimcore | <10.3.1 | 10.3.1 |
Pimcore Pimcore | <10.3.1 | |
<10.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0565 is a Cross-site Scripting vulnerability found in Packagist pimcore/pimcore prior to version 10.3.1.
CVE-2022-0565 has a severity of high (7) based on the CVSS score.
CVE-2022-0565 exposes sensitive information to an unauthorized actor in Packagist pimcore/pimcore prior to version 10.3.1.
The remedy for CVE-2022-0565 is to update Packagist pimcore/pimcore to version 10.3.1 or later.
You can find more information about CVE-2022-0565 at the following references: [link](https://nvd.nist.gov/vuln/detail/CVE-2022-0565), [link](https://github.com/pimcore/pimcore/commit/7697f709a501860144352696e583a2533a6e1245), [link](https://huntr.dev/bounties/b0b29656-4bbe-41cf-92f6-8579df0b6de5).