{"id":"CVE-2023-2629","aliases":["GHSA-mq3x-qgwx-3rfw"],"url":"https://o3.security/vulnerability/CVE-2023-2629","summary":"Improper Neutralization of Formula Elements in a CSV File in pimcore/customer-data-framework","details":"Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9.","published":"2023-05-10T00:00:00Z","modified":"2026-08-12T03:51:22.073102311Z","cvss":{"score":5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:L"},"epss":{"score":0.00406,"percentile":0.34072,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"pimcore/customer-management-framework-bundle","fixedVersion":"3.3.9"}],"fix":{"url":"https://github.com/pimcore/customer-data-framework/commit/4e0105c3a78d20686a0c010faef27d2297b98803","label":"pimcore/customer-data-framework@4e0105c"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/821ff465-4754-42d1-9376-813c17f16a01"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/2xxx/CVE-2023-2629.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-2629"},{"type":"FIX","url":"https://github.com/pimcore/customer-data-framework/commit/4e0105c3a78d20686a0c010faef27d2297b98803"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:22.073102311Z"}}