CVE-2018-14059
MEDIUMPimcore - XSS
Title source: llmDescription
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions.
Exploits (1)
References (4)
Scores
CVSS v3
5.4
EPSS
0.0001
EPSS Percentile
0.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
pimcore/pimcore
< 5.2.3
pimcore/pimcore
0 - 5.3.0Packagist
Published
Aug 24, 2018
Tracked Since
Feb 18, 2026