First published: Fri Jul 21 2023(Updated: )
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4.
Credit: security@huntr.dev security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Pimcore Pimcore | <10.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-3822 is medium.
CVE-2023-3822 is a Cross-site Scripting (XSS) vulnerability that allows reflected XSS attacks in the GitHub repository pimcore/pimcore prior to version 10.6.4.
The software affected by CVE-2023-3822 is pimcore/pimcore versions prior to 10.6.4.
To fix CVE-2023-3822, you should upgrade to version 10.6.4 of pimcore/pimcore.
You can find more information about CVE-2023-3822 at the following references: [Link 1](https://github.com/pimcore/pimcore/commit/d75888a9b14baaad591548463cca09dfd1395236), [Link 2](https://huntr.dev/bounties/2a3a13fe-2a9a-4d1a-8814-fd8ed1e3b1d5), [Link 3](https://nvd.nist.gov/vuln/detail/CVE-2023-3822).