MEDIUM
Cross-site Scripting (XSS) - Stored in pimcore/pimcore
Published Mar 15, 2022
5.4
MEDIUMCVSS 3.1
EPSS 0.80%
Description
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
Affected products
-
Affected
- ≥ unspecified, < 10.4.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Pimcore | Pimcore/pimcore | unknown | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1422 Advisory
- https://github.com/advisories/GHSA-g795-4hxx-qqwm Advisory
- https://github.com/pimcore/pimcore/commit/6e0922c5b2959ac1b48500ac508d8fc5a97286f9 x_refsource_MISCPatchThird Party Advisory
- https://github.com/pimcore/pimcore/pull/11447
- https://huntr.dev/bounties/2859a1c1-941c-4efc-a3ad-a0657c7a77e9 x_refsource_CONFIRMExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0893
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1422 | Advisory | |
| https://github.com/advisories/GHSA-g795-4hxx-qqwm | Advisory | |
| https://github.com/pimcore/pimcore/commit/6e0922c5b2959ac1b48500ac508d8fc5a97286f9 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/pimcore/pimcore/pull/11447 | ||
| https://huntr.dev/bounties/2859a1c1-941c-4efc-a3ad-a0657c7a77e9 | x_refsource_CONFIRMExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0893 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Mar 15, 2022
Updated Aug 2, 2024
Reserved Mar 9, 2022
Link CVE-2022-0893
CISA Vulnrichment
No data
Red Hat
No data
GitHub
Link GHSA-G795-4HXX-QQWM