CVE-2018-14059

MEDIUM

Pimcore - XSS

Title source: llm

Description

Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions.

Exploits (1)

exploitdb WRITEUP
by SEC Consult · textwebappsphp
https://www.exploit-db.com/exploits/45208

Scores

CVSS v3 5.4
EPSS 0.0001
EPSS Percentile 0.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
pimcore/pimcore < 5.2.3
pimcore/pimcore 0 - 5.3.0Packagist
Published Aug 24, 2018
Tracked Since Feb 18, 2026