First published: Thu May 11 2023(Updated: )
The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management. In `pimcore/customer-management-framework-bundle` prior to version 3.3.9, business logic errors are possible in the `Conditions` tab since the counter can be a negative number. This vulnerability is capable of the unlogic in the counter value in the Conditions tab. Users should update to version 3.3.9 to receive a patch or, as a workaround, or apply the patch manually.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pimcore Customer Management Framework | <3.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32075 is a vulnerability in the Customer Management Framework (CMF) for Pimcore that allows for business logic errors in the Conditions tab.
CVE-2023-32075 has a severity of 4.3, which is considered medium.
CVE-2023-32075 affects the 'pimcore/customer-management-framework-bundle' prior to version 3.3.9, causing possible business logic errors in the Conditions tab.
To fix CVE-2023-32075, update 'pimcore/customer-management-framework-bundle' to version 3.3.9 or later.
Yes, a patch for CVE-2023-32075 is available at the following link: [Patch Link](https://github.com/pimcore/customer-data-framework/commit/e3f333391582d9309115e6b94e875367d0ea7163.patch).