First published: Thu Nov 30 2023(Updated: )
Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSRF attacks from occurring, therefore an attacker could abuse this vulnerability to create new customers. This issue has been patched in version 4.0.5.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pimcore Pimcore | <4.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID for this vulnerability is CVE-2023-49076.
The title of this vulnerability is Pimcore missing token/header to prevent CSRF.
The severity of CVE-2023-49076 is medium with a score of 6.5.
An attacker can exploit this vulnerability by abusing the lack of tokens or headers to prevent CSRF attacks, allowing them to create new customers.
To fix CVE-2023-49076, update to version 4.0.5 of Pimcore as the issue has been patched in this version.