CVE-2024-49370
- EPSS 0.01%
- Veröffentlicht 23.10.2024 15:15:31
- Zuletzt bearbeitet 06.11.2024 22:31:30
Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser and "Use Pimcore Backend Password" is set to true, the change password function in Portal Profile sets the new password. Prior to...
CVE-2024-32871
- EPSS 0.01%
- Veröffentlicht 04.06.2024 15:15:45
- Zuletzt bearbeitet 21.11.2024 09:15:54
Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. By changing the file extension or scaling factor of the requested thumbnail, attackers can create file...
CVE-2024-29197
- EPSS 0%
- Veröffentlicht 26.03.2024 15:15:49
- Zuletzt bearbeitet 05.11.2025 22:18:50
Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true` allows to view unpublished sites. In previous versions of Pimcore, session information would propagate to previews, so only a lo...
CVE-2023-49076
- EPSS 0.01%
- Veröffentlicht 30.11.2023 06:15:46
- Zuletzt bearbeitet 21.11.2024 08:32:46
Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSRF attacks from occurring, therefore an attacker could abuse this vulnerability to create new customers. This issue has been patche...
CVE-2023-47637
- EPSS 73.77%
- Veröffentlicht 15.11.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:30:34
Pimcore is an Open Source Data & Experience Management Platform. In affected versions the `/admin/object/grid-proxy` endpoint calls `getFilterCondition()` on fields of classes to be filtered for, passing input from the request, and later executes the...
CVE-2023-5873
- EPSS 0%
- Veröffentlicht 31.10.2023 09:15:09
- Zuletzt bearbeitet 21.11.2024 08:42:41
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 11.1.0.
CVE-2023-4453
- EPSS 0%
- Veröffentlicht 21.08.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 08:35:11
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.8.
CVE-2023-38708
- EPSS 0%
- Veröffentlicht 04.08.2023 01:15:09
- Zuletzt bearbeitet 21.11.2024 08:14:05
Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exists in the `AssetController::importServerFilesAction`, which allows an attacker to overwrite or modify ...
CVE-2023-3819
- EPSS 0%
- Veröffentlicht 21.07.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 08:18:08
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4.
CVE-2023-3820
- EPSS 36.47%
- Veröffentlicht 21.07.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 08:18:08
SQL Injection in GitHub repository pimcore/pimcore prior to 10.6.4.