First published: Wed May 10 2023(Updated: )
### Impact Execute Javascript code on victim browsers and potentially steal cookies to takeover their account. ### Patches Update to version 10.5.21 or apply this patches manually https://github.com/pimcore/pimcore/commit/7e32cc28145274ddfc30fb791012d26c1278bd38.patch ### Workarounds Apply patches manually: https://github.com/pimcore/pimcore/commit/7e32cc28145274ddfc30fb791012d26c1278bd38.patch ### References https://huntr.dev/bounties/e1001870-b8d8-4921-8b9c-bbdfb1a1491e/
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Pimcore Pimcore | <10.5.21 | |
composer/pimcore/pimcore | <10.5.21 | 10.5.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-2630 is medium, with a severity value of 4.8.
CVE-2023-2630 affects Pimcore versions prior to 10.5.21.
The CWE number for CVE-2023-2630 is 79.
To fix the Cross-site Scripting (XSS) vulnerability CVE-2023-2630, update your Pimcore installation to version 10.5.21 or above.
Yes, you can find references for CVE-2023-2630 at the following links: [link1], [link2].