VulnerabilityModified
CVE-2023-28850
Pimcore Perspective Editor provides an editor for Pimcore that allows users to add/remove/edit custom views and perspectives.
MEDIUM 5.4EPSS 0.57%
Does this matter?
Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.
Description
Pimcore Perspective Editor provides an editor for Pimcore that allows users to add/remove/edit custom views and perspectives. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Version 1.5.1 has a patch. As a workaround, one may apply the patch manually.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.57% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- pimcore/perspective editor
- Source
- security-advisories@github.com
References
- https://github.com/pimcore/perspective-editor/pull/121.patchMailing List, Patch
- https://github.com/pimcore/perspective-editor/security/advisories/GHSA-fq8q-55v3-2986Exploit, Patch, Vendor Advisory
- https://huntr.dev/bounties/5529f51e-e40f-46f1-887b-c9dbebab4f06/Exploit, Issue Tracking, Patch, Third Party Advisory
- https://github.com/pimcore/perspective-editor/pull/121.patchMailing List, Patch
- https://github.com/pimcore/perspective-editor/security/advisories/GHSA-fq8q-55v3-2986Exploit, Patch, Vendor Advisory
- https://huntr.dev/bounties/5529f51e-e40f-46f1-887b-c9dbebab4f06/Exploit, Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.