First published: Mon Feb 13 2023(Updated: )
An improper SameSite Attribute vulnerability in pimCore v10.5.15 allows attackers to execute arbitrary code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pimcore E-commerce Framework | =10.5.15 | |
composer/pimcore/pimcore | <10.5.16 | 10.5.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25240 is a critical vulnerability allowing arbitrary code execution due to improper SameSite Attribute implementation.
To fix CVE-2023-25240, update Pimcore to version 10.5.16 or later where the vulnerability is patched.
Pimcore version 10.5.15 is affected by CVE-2023-25240.
Yes, CVE-2023-25240 can potentially lead to data compromise by allowing attackers to execute arbitrary code.
No, CVE-2023-25240 can be exploited without authentication.