CVE-2023-2332

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Nov 15, 2024
CWE ID 798

Summary

CVE-2023-2332 is a stored Cross-site Scripting (XSS) vulnerability identified in the Conditions tab of Pricing Rules within pimcore's version 10.5.19. The issue lies in the From and To fields of the Date Range section, which can be exploited by attackers to inject malicious scripts. These scripts can be executed in the user's browser context, potentially leading to data theft, such as cookie stealing, or redirection to malicious sites. This vulnerability has been addressed in the updated version 10.5.21.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share