ZeroHour

CVE-2023-49076

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p18
Published
()
Modified
Description

Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSRF attacks from occurring, therefore an attacker could abuse this vulnerability to create new customers. This issue has been patched in version 4.0.5.

Vendors
pimcore
Products
pimcore
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.