GHSA-m988-7375-7g2c

    Dashboard / Vulnerabilities / GHSA-m988-7375-7g2c

    GHSA-m988-7375-7g2c

    Published: 25 Sept 2023Last Modified: 10 Sept 2026

    Summary: pimcore/admin-ui-classic-bundle Cross-site Scripting vulnerability in Translations

    Details: ### Impact The translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user. The translations may be accessible by a user with comparatively lower overall access (as the translation permission cannot be scoped to certain “modules”) and a skilled attacker might be able to exploit the parsing of the translation string in the dialog box. ### Patches https://github.com/pimcore/admin-ui-classic-bundle/commit/abd7739298f974319e3cac3fd4fcd7f995b63e4c.patch ### Workarounds Update to version 1.1.2 or apply this patches manually https://github.com/pimcore/admin-ui-classic-bundle/commit/abd7739298f974319e3cac3fd4fcd7f995b63e4c.patch

    Affected packages

    Package

    Name: pimcore/admin-ui-classic-bundle

    Purl: pkg:composer/pimcore/admin-ui-classic-bundle

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.1.2

    Affected versions

    v1.0.0
    v1.0.0-BETA1
    v1.0.0-RC1
    v1.0.0-RC2
    v1.0.1
    v1.0.2
    v1.0.3
    v1.0.4
    v1.0.5
    v1.0.6

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-m988-7375-7g2c | CVE-DB