First published: Mon Apr 03 2023(Updated: )
Pimcore Perspective Editor provides an editor for Pimcore that allows users to add/remove/edit custom views and perspectives. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Version 1.5.1 has a patch. As a workaround, one may apply the patch manually.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pimcore Perspective Editor | <1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28850 is a vulnerability in Pimcore Perspective Editor that allows unauthorized access and potential cookie theft.
CVE-2023-28850 can lead to unauthorized access to a user's account or redirect users to malicious websites.
Pimcore Perspective Editor version up to and excluding 1.5.1 is affected by CVE-2023-28850.
CVE-2023-28850 has a severity rating of medium, with a value of 5.4.
Users should upgrade to a version of Pimcore Perspective Editor that is not affected by CVE-2023-28850.