Sept. 25, 2023, 7:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%sâ€� (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user. The translations may be accessible by a user with comparatively lower overall access (as the translation permission cannot be scoped to certain “modulesâ€�) and a skilled attacker might be able to exploit the parsing of the translation string in the dialog box. This issue has been patched in …

access admin backend bundle cve may permission text translation value

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Information System Security Engineer 2

@ Wyetech | Annapolis Junction, Maryland

Staff Vulnerability/Configuration Management Security Engineer

@ ServiceNow | Hyderabad, India

Security Engineer

@ AXS | London, England, UK