CVE-2021-39170
Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could ad
Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets. There is a patch for this issue in Pimcore version 10.1.2.
As a workaround, users may apply the patch manually.
HIGH · CVSS 8
EPSS 0.00027
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0