Pimcore vulnerable to Cross-site Scripting in UrlSlug Data type
Vulnerability Description
Pimcore is an open source data and experience management platform. Prior to version 10.5.19, an attacker can use cross-site scripting to send a malicious script to an unsuspecting user. Users may upgrade to version 10.5.19 to receive a patch or, as a workaround, apply the patch manually.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-28106
Credits & Attribution
No credits recorded in the NVD database.
References
More from pimcore
View All →Affected Vendor
pimcore
View all reports →