First published: Wed May 10 2023(Updated: )
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Pimcore Pimcore | <10.5.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2616 is a vulnerability that allows cross-site scripting (XSS) attacks in the GitHub repository pimcore/pimcore prior to version 10.5.21.
An attacker can exploit the cross-site scripting (XSS) vulnerability in CVE-2023-2616 by injecting malicious scripts into the pimcore/pimcore application, which are then executed in the browser of other users visiting the affected site.
CVE-2023-2616 has a severity score of 5.4, which is considered medium.
To fix CVE-2023-2616, upgrade the pimcore/pimcore application to version 10.5.21 or later.
You can find more information about CVE-2023-2616 in the GitHub repository commit [here](https://github.com/pimcore/pimcore/commit/07a2c95be524c7e20105cef58c5767d4ebb06091) and the Huntr bounty report [here](https://huntr.dev/bounties/564cb512-2bcc-4458-8c20-88110ab45801).