CVE detail
CVE-2023-46722 — CVE-2023-46722
Published 2023-10-31 · Modified 2026-06-17 · Vendor pimcore · Product admin_classic_bundle · Source nvd
MEDIUM
severity
CVSS-derived band
0.0050
EPSS probability
exploitation probability, 30d
40.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Users should upgrade to version 1.2.0 to receive a patch or, as a workaround, apply the patch manually.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References