Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:42145
HistoryAug 05, 2023 - 4:28 a.m.

Cross-Site Scripting (XSS)

2023-08-0504:28:47
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
xss
pimcore
email templates
html sanitization
malicious site
login credentials

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

23.9%

pimcore/customer-management-framework-bundle is vulnerable to Cross-Site Scripting (XSS) attacks. The vulnerability is due a lack of HTML sanitization in email templates, which allows an attacker to send an email which when a link is clicked, redirects the user to a malicious site enabling attackers to access the victim’s login credentials.

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

23.9%

Related for VERACODE:42145