CVE-2023-2332 MEDIUM

CVE-2023-2332: Stored Cross-site Scripting (XSS) in pimcore/pimcore

Vendor Pimcore
Product pimcore/pimcore
Weakness CWE-79 · XSS
Published November 15, 2024
Last update November 15, 2024

CVSS base score

4.0/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

A stored Cross-site Scripting (XSS) vulnerability exists in the Conditions tab of Pricing Rules in pimcore/pimcore versions 10.5.19. The vulnerability is present in the From and To fields of the Date Range section, allowing an attacker to inject malicious scripts. This can lead to the execution of arbitrary JavaScript code in the context of the user's browser, potentially stealing cookies or redirecting users to malicious sites. The issue is fixed in version 10.5.21.

Key dates

02Disclosure timeline

November 15, 2024 CVE published
November 15, 2024 Record updated