MEDIUM
Cross-site Scripting (XSS) - Stored in pimcore/customer-data-framework
Published Aug 3, 2023
5.4
MEDIUMCVSS 3.1
EPSS 0.61%
Description
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<3.4.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Pimcore | Pimcore/customer-Data-Framework | n/a |
|
- < 3.4.2
-
- Version 0StatusaffectedConstraints<3.4.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Pimcore | Customer-Data-Framework | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://github.com/advisories/GHSA-735f-w79p-282x Advisory
- https://github.com/pimcore/customer-data-framework/commit/72f45dd537a706954e7a71c99fbe318640e846a2 Patch
- https://github.com/pimcore/customer-data-framework/commit/72f45dd537a706954e7a71c99fbe318640e846a2.patch
- https://github.com/pimcore/customer-data-framework/security/advisories/GHSA-735f-w79p-282x
- https://huntr.dev/bounties/ce852777-2994-40b4-bb4e-c4d10023eeb0 ExploitPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-4145
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Aug 3, 2023
Updated Oct 11, 2024
Reserved Aug 3, 2023
Link CVE-2023-4145
CISA Vulnrichment
GHSA-735F-W79P-282X Updated Oct 11, 2024