Vulnerabilities > Pimcore > Pimcore > 5.2.2

DATE CVE VULNERABILITY TITLE RISK
2018-08-24 CVE-2018-14059 Cross-site Scripting vulnerability in Pimcore
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions.
network
low complexity
pimcore CWE-79
5.4
2018-08-17 CVE-2018-14058 SQL Injection vulnerability in Pimcore
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
network
low complexity
pimcore CWE-89
6.5
2018-08-17 CVE-2018-14057 Cross-Site Request Forgery (CSRF) vulnerability in Pimcore
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function.
network
low complexity
pimcore CWE-352
8.8