CVE-2024-11954

LOW

Pimcore 11.4.2 - XSS

Title source: llm

Description

A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown functionality of the component Search Document. The manipulation leads to basic cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Exploits (1)

exploitdb WORKING POC
by maeitsec · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52194

Scores

CVSS v3 2.4
EPSS 0.0033
EPSS Percentile 56.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-80 CWE-74
Status published
Products (2)
pimcore/pimcore 11.4.2
pimcore/pimcore 11.4.2 - 11.5.3Packagist
Published Jan 28, 2025
Tracked Since Feb 18, 2026