Skip to content

Duplicate Advisory: pimcore is vulnerable to cross-site scripting in translate module

Moderate severity GitHub Reviewed Published Mar 29, 2023 to the GitHub Advisory Database • Updated Mar 31, 2023
Withdrawn This advisory was withdrawn on Mar 31, 2023

Package

composer pimcore/pimcore (Composer)

Affected versions

< 10.5.20

Patched versions

10.5.20

Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-hfmg-g39c-5444. This link is maintained ot preserve external references.

Original Description

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.20.

References

Published by the National Vulnerability Database Mar 29, 2023
Published to the GitHub Advisory Database Mar 29, 2023
Reviewed Mar 30, 2023
Last updated Mar 31, 2023
Withdrawn Mar 31, 2023

Severity

Moderate

EPSS score

Weaknesses

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. Learn more on MITRE.

CVE ID

No known CVE

GHSA ID

GHSA-rp78-4562-gx3c

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.