Skip to content

Cross-site Scripting (XSS) in Translations

Moderate
dvesh3 published GHSA-m988-7375-7g2c Sep 25, 2023

Package

composer pimcore/admin-ui-classic-bundle (Composer)

Affected versions

< 1.1.2

Patched versions

1.1.2

Description

Impact

The translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user.

The translations may be accessible by a user with comparatively lower overall access (as the translation permission cannot be scoped to certain “modules”) and a skilled attacker might be able to exploit the parsing of the translation string in the dialog box.

Patches

https://github.com/pimcore/admin-ui-classic-bundle/commit/abd7739298f974319e3cac3fd4fcd7f995b63e4c.patch

Workarounds

Update to version 1.1.2 or apply this patches manually
https://github.com/pimcore/admin-ui-classic-bundle/commit/abd7739298f974319e3cac3fd4fcd7f995b63e4c.patch

Severity

Moderate

CVE ID

CVE-2023-42817

Weaknesses

Credits