Skip to content

Cross-site Scripting (XSS) in UrlSlug Data type

Moderate
dvesh3 published GHSA-x5j3-mq9g-8jc8 Mar 16, 2023

Package

composer pimcore/pimcore (Composer)

Affected versions

< 10.5.19

Patched versions

10.5.19

Description

Impact

An attacker can use XSS to send a malicious script to an unsuspecting user.

Patches

Update to version 10.5.19 or apply this patch manually https://github.com/pimcore/pimcore/pull/14669.patch

Workarounds

Apply https://github.com/pimcore/pimcore/pull/14669.patch manually.

References

https://huntr.dev/bounties/fa77d780-9b23-404b-8c44-12108881d11a

Severity

Moderate

CVE ID

CVE-2023-28106

Weaknesses