{"id":"CVE-2023-46722","aliases":["GHSA-jfxw-6c5v-c42f"],"url":"https://o3.security/vulnerability/CVE-2023-46722","summary":"Pimcore Admin Classic Bundle Cross-site Scripting (XSS) in PDF previews","details":"### Impact\nThis vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites.\n\nProof of Concept\nStep 1. Go to /admin and login.\nStep 2. In Documents, go to home -> click on Sample Content -> click Document folder\nStep 3. Upload file PDF content XSS payload\n\n### Patches\nApply patches \nhttps://github.com/pimcore/pimcore/commit/757375677dc83a44c6c22f26d97452cc5cda5d7c.patch\nhttps://github.com/pimcore/admin-ui-classic-bundle/commit/19fda2e86557c2ed4978316104de5ccdaa66d8b9.patch\n\n### Workarounds\nUpdate to version 1.2.0 or apply patches manually\nhttps://github.com/pimcore/pimcore/commit/757375677dc83a44c6c22f26d97452cc5cda5d7c.patch\nhttps://github.com/pimcore/admin-ui-classic-bundle/commit/19fda2e86557c2ed4978316104de5ccdaa66d8b9.patch","published":"2023-10-31T15:36:49.932Z","modified":"2026-08-12T03:51:26.744729198Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"pimcore/admin-ui-classic-bundle","fixedVersion":"1.2.0"}],"fix":{"url":"https://github.com/pimcore/admin-ui-classic-bundle/commit/19fda2e86557c2ed4978316104de5ccdaa66d8b9","label":"pimcore/admin-ui-classic-bundle@19fda2e"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/46xxx/CVE-2023-46722.json"},{"type":"ADVISORY","url":"https://github.com/pimcore/admin-ui-classic-bundle/security/advisories/GHSA-jfxw-6c5v-c42f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-46722"},{"type":"FIX","url":"https://github.com/pimcore/admin-ui-classic-bundle/commit/19fda2e86557c2ed4978316104de5ccdaa66d8b9"},{"type":"FIX","url":"https://github.com/pimcore/pimcore/commit/757375677dc83a44c6c22f26d97452cc5cda5d7c"},{"type":"PACKAGE","url":"https://github.com/pimcore/admin-ui-classic-bundle"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.744729198Z"}}