CVE-2023-30848 – Pimcore SQL Injection Vulnerability in Admin Search Find API
https://notcve.org/view.php?id=CVE-2023-30848
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the admin search find API has a SQL injection vulnerability. Users should upgrade to version 10.5.21 to receive a patch or, as a workaround, apply the patch manually. • https://github.com/pimcore/pimcore/commit/25ad8674886f2b938243cbe13e33e204a2e35cc3.patch https://github.com/pimcore/pimcore/pull/14972 https://github.com/pimcore/pimcore/security/advisories/GHSA-6mhm-gcpf-5gr8 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-2336 – Path Traversal in pimcore/pimcore
https://notcve.org/view.php?id=CVE-2023-2336
Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21. • https://github.com/pimcore/pimcore/commit/498cadec2292f7842fb10612068ac78496e884b4 https://huntr.dev/bounties/af764624-7746-4f53-8480-85348dbb4f14 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2023-2322 – Cross-site Scripting (XSS) - Stored in pimcore/pimcore
https://notcve.org/view.php?id=CVE-2023-2322
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21. • https://github.com/pimcore/pimcore/commit/9fc674892b8b53103098b9524705074a45e7f773 https://huntr.dev/bounties/f7228f3f-3bef-46fe-b0e3-56c432048a67 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-2323 – Cross-site Scripting (XSS) - Stored in pimcore/pimcore
https://notcve.org/view.php?id=CVE-2023-2323
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21. • https://github.com/pimcore/pimcore/commit/e88fa79de7b5903fb58ddbc231130b04d937d79e https://huntr.dev/bounties/41edf190-f6bf-4a29-a237-7ff1b2d048d3 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-2327 – Cross-site Scripting (XSS) - Stored in pimcore/pimcore
https://notcve.org/view.php?id=CVE-2023-2327
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21. • https://github.com/pimcore/pimcore/commit/fb3056a21d439135480ee299bf1ab646867b5f4f https://huntr.dev/bounties/7336b71f-a36f-4ce7-a26d-c8335ac713d6 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •