5.4
CVSSv3

CVE-2018-14059

Published: 24/08/2018 Updated: 01/11/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pimcore pimcore

Exploits

SEC Consult Vulnerability Lab Security Advisory < 20180813-0 > ======================================================================= title: SQL Injection, XSS & CSRF vulnerabilities product: Pimcore vulnerable version: 523 and below fixed version: 530 CVE number: CVE-2018-14057, CVE-2018-140 ...
Pimcore versions 523 and below suffer from cross site request forgery, cross site scripting, and remote SQL injection vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> SEC Consult SA-20180813-0 :: SQL Injection, XSS &amp; CSRF vulnerabilities in Pimcore <!--X-Subject-Header-End--> <!-- ...