CVE-2023-32075 – Pimcore vulnerable to Business Logic Errors in Customer automation rules
https://notcve.org/view.php?id=CVE-2023-32075
The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management. In `pimcore/customer-management-framework-bundle` prior to version 3.3.9, business logic errors are possible in the `Conditions` tab since the counter can be a negative number. This vulnerability is capable of the unlogic in the counter value in the Conditions tab. Users should update to version 3.3.9 to receive a patch or, as a workaround, or apply the patch manually. • https://github.com/pimcore/customer-data-framework/commit/e3f333391582d9309115e6b94e875367d0ea7163.patch https://github.com/pimcore/customer-data-framework/releases/tag/v3.3.9 https://github.com/pimcore/customer-data-framework/security/advisories/GHSA-x99j-r8vv-gwwj https://huntr.dev/bounties/cecd7800-a996-4f3a-8689-e1c2a1e0248a • CWE-20: Improper Input Validation •
CVE-2023-2614 – Cross-site Scripting (XSS) - DOM in pimcore/pimcore
https://notcve.org/view.php?id=CVE-2023-2614
Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21. • https://github.com/pimcore/pimcore/commit/c36ef54ce33f7b5e74b7b0ab9eabfed47c018fc7 https://huntr.dev/bounties/1a5e6c65-2c5e-4617-9411-5b47a7e743a6 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-2615 – Cross-site Scripting (XSS) - Reflected in pimcore/pimcore
https://notcve.org/view.php?id=CVE-2023-2615
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21. • https://github.com/pimcore/pimcore/commit/7a799399e6843cd049e85da27ceb75b78505317f https://huntr.dev/bounties/af9c360a-87f8-4e97-a24b-6db675ee942a • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-2616 – Cross-site Scripting (XSS) - Generic in pimcore/pimcore
https://notcve.org/view.php?id=CVE-2023-2616
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21. • https://github.com/pimcore/pimcore/commit/07a2c95be524c7e20105cef58c5767d4ebb06091 https://huntr.dev/bounties/564cb512-2bcc-4458-8c20-88110ab45801 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-2630 – Cross-site Scripting (XSS) - Stored in pimcore/pimcore
https://notcve.org/view.php?id=CVE-2023-2630
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21. • https://github.com/pimcore/pimcore/commit/7e32cc28145274ddfc30fb791012d26c1278bd38 https://huntr.dev/bounties/e1001870-b8d8-4921-8b9c-bbdfb1a1491e • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •