JiaJia Ji
21 exploits
Active since Mar 2022
Pimcore E-Commerce Framework < 1.0.10 - Authenticated Improper Access Control in Admin Order List
CVSS 4.3
pimcore < 11.5.4 - Authenticated SQL Injection via Filter String
CVSS 8.8
Pimcore <=11.5.14.1/12.3.2 - SQL Injection
CVSS 4.9
pimcore < 10.3.3 - Stored Cross-Site Scripting
CVSS 5.4
pimcore < 10.3.3 - Stored Cross-Site Scripting
CVSS 5.4
pimcore < 10.5.20 - Stored Cross-Site Scripting
CVSS 5.4
pimcore < 10.5.16 - Authenticated Unrestricted Upload of File with Dangerous Type via User Profile Update
CVSS 8.2
pimcore < 10.3.3 - Stored Cross-Site Scripting
CVSS 5.4
pimcore customer_management_framework < 3.3.10 - SQL Injection
CVSS 7.2
pimcore/pimcore <10.5.23 - Privilege Escalation
CVSS 8.8
pimcore/customer-data-framework <3.4.1 - Info Disclosure
CVSS 6.5
pimcore < 10.5.24 - SQL Injection
CVSS 7.2
pimcore < 10.6.4 - SQL Injection
CVSS 7.2
Pimcore admin-ui-classic-bundle < 1.1.2 - Cross-Site Scripting via Translation String Parsing
CVSS 5.4
pimcore admin_classic_bundle < 1.1.4 and admin-ui-classic-bundle < 1.2.0-RC1 - Unverified Password Change
CVSS 7.2
pimcore customer_management_framework < 4.0.6 - Authenticated Improper Access Control in GDPR Data Extraction
CVSS 6.5
Pimcore <1.3.4 - Host Header Injection
CVSS 8.1
pimcore/admin-ui-classic-bundle < 1.7.4 - User Enumeration via Forgot Password Error Message
CVSS 5.3
Pimcore <12.3.1-11.5.14 - Info Disclosure
CVSS 8.6
Pimcore <2.2.3-1.7.16 - Info Disclosure
CVSS 4.3
Pimcore Web2Print Tools Bundle <6.1.1 - Privilege Escalation
CVSS 5.4