Pimcore
Pimcore Customer Management Framework: vulnerabilidades y CVE
Pimcore Customer Management Framework tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-21667 | Media (6.5) | 0.59% | — | 11 ene 2024 | pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorized user can access the GDPR data extraction feature and query over the… |
| CVE-2024-21666 | Media (6.5) | 0.56% | — | 11 ene 2024 | The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing automation. An authenticated and unauthorized user can access the list of… |
| CVE-2023-4145 | Media (5.4) | 0.61% | — | 3 ago 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2. |
| CVE-2023-3574 | Media (6.5) | 0.54% | — | 10 jul 2023 | Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1. |
| CVE-2023-2881 | Media (4.9) | 0.55% | — | 25 may 2023 | Storing Passwords in a Recoverable Format in GitHub repository pimcore/customer-data-framework prior to 3.3.10. |
| CVE-2023-2756 | Alta (7.2) | 0.94% | — | 17 may 2023 | SQL Injection in GitHub repository pimcore/customer-data-framework prior to 3.3.10. |
| CVE-2023-32075 | Media (4.3) | 0.76% | — | 11 may 2023 | The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management. In `pimcore/customer-management-framework-bundle` prior to version 3.3.9, business logic errors are possible in the… |
| CVE-2023-2629 | Alta (7.8) | 0.41% | — | 10 may 2023 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9. |
| CVE-2021-31867 | Alta (7.5) | 1.2% | — | 4 ago 2021 | Pimcore Customer Data Framework version 3.0.0 and earlier suffers from a Boolean-based blind SQL injection issue in the $id parameter of the SegmentAssignmentController.php component of the application. This issue was… |