Customer-data-framework allows... CVE-2023-49076

- AV AC AU C I A
发布: 2023-11-30
修订: 2023-12-05

Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSRF attacks from occurring, therefore an attacker could abuse this vulnerability to create new customers. This issue has been patched in version 4.0.5.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息