CVE-2024-11954

LOW

Pimcore 11.4.2 - XSS

Title source: llm

Description

A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown functionality of the component Search Document. The manipulation leads to basic cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Exploits (1)

exploitdb WORKING POC
by maeitsec · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52194

Scores

CVSS v3 2.4
EPSS 0.0033
EPSS Percentile 55.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

Classification

CWE
CWE-80 CWE-74
Status published

Affected Products (2)

pimcore/pimcore
pimcore/pimcore < 11.5.3Packagist

Timeline

Published Jan 28, 2025
Tracked Since Feb 18, 2026