First published: Thu Aug 03 2023(Updated: )
### Impact As HTML injection works in email an attacker can trick a victim to click on such hyperlinks to redirect him to any malicious site and also can host a XSS page. All this will surely cause some damage to the victim. This could lead to users being tricked into giving logins away to malicious attackers. ### Patches Update to version 3.4.2 or apply this patch manually https://github.com/pimcore/customer-data-framework/commit/72f45dd537a706954e7a71c99fbe318640e846a2.patch ### Workarounds Apply https://github.com/pimcore/customer-data-framework/commit/72f45dd537a706954e7a71c99fbe318640e846a2.patch manually. ### References https://huntr.dev/bounties/ce852777-2994-40b4-bb4e-c4d10023eeb0/
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
composer/pimcore/customer-management-framework-bundle | <3.4.2 | 3.4.2 |
Pimcore Customer Data Framework | <3.4.2 | |
<3.4.2 |
https://github.com/pimcore/customer-data-framework/commit/72f45dd537a706954e7a71c99fbe318640e846a2
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-4145.
The severity of CVE-2023-4145 is medium with a severity value of 6.5.
This vulnerability allows an attacker to trick users into clicking on malicious hyperlinks, leading to potential damage including giving away login information.
The software versions affected by CVE-2023-4145 are prior to version 3.4.2 of the pimcore/customer-management-framework-bundle package and the Pimcore Customer Data Framework.
To fix this vulnerability, ensure that you update to version 3.4.2 or later of the pimcore/customer-management-framework-bundle package and the Pimcore Customer Data Framework.