CVSS 3.1 Score 6.5 of 10 (medium)


Published Nov 30, 2023
Updated: Dec 5, 2023
CWE ID 352


CVE-2023-49076 is a vulnerability in the customer-data-framework used for managing customer data within Pimcore. This vulnerability allows for CSRF attacks to occur, as there are no tokens or headers in place to prevent them. Exploiting this vulnerability could enable an attacker to create new customers. The issue has been patched in version 4.0.5 of the affected products. With a base severity of MEDIUM and an impact score of 3.6, this vulnerability poses a potential risk to organizations, particularly in terms of integrity impact.


Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-49076 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options