HomePimcoreCVE-2023-32075

CVE-2023-32075

MEDIUM
4.3CVSS
Published: 2023-05-11
Updated: 2024-11-21
AI Analysis

Description

The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management. In `pimcore/customer-management-framework-bundle` prior to version 3.3.9, business logic errors are possible in the `Conditions` tab since the counter can be a negative number. This vulnerability is capable of the unlogic in the counter value in the Conditions tab. Users should update to version 3.3.9 to receive a patch or, as a workaround, or apply the patch manually.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
network
Complexity
low
Privileges
low
User Action
none
Scope
unchanged
Confidentiality
none
Integrity
low
Availability
none
Weaknesses
CWE-20NVD-CWE-noinfo

Metadata

Primary Vendor
PIMCORE
Published
5/11/2023
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

pimcore : customer_management_framework

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2023-32075 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com