← Volver a CVEs
CVE-2021-39166
HIGH8.0
Descripcion
Pimcore is an open source data & experience management platform. Prior to version 10.1.2, text-values were not properly escaped before printed in the version preview. This allowed XSS by authenticated users with access to the resources. This issue is patched in Pimcore version 10.1.2.
Detalles CVE
Puntuacion CVSS v3.18.0
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioREQUIRED
Publicado9/1/2021
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
pimcore:pimcore
Debilidades (CWE)
CWE-79
Referencias
https://github.com/pimcore/pimcore/pull/10170(security-advisories@github.com)
https://github.com/pimcore/pimcore/security/advisories/GHSA-w6j8-jc36-x5q9(security-advisories@github.com)
https://github.com/pimcore/pimcore/pull/10170(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/pimcore/pimcore/security/advisories/GHSA-w6j8-jc36-x5q9(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.