CVE-2021-37702

pimcore/pimcore
on github

Published

Severity

CVSS v3:
8.8 HIGH
CVSS v2:
6.5 MEDIUM

Description

Pimcore is an open source data & experience management platform. Prior to version 10.1.1, Data Object CSV import allows formular injection. The problem is patched in 10.1.1. Aside from upgrading, one may apply the patch manually as a workaround.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:pimcore:pimcore:*:*:*:*:*:*:*:*n/a10.1.1*

External Links