CVE-2023-49076: medium-severity vulnerability in pimcore customer-data-framework
Pimcore missing token/header to prevent CSRF
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.3epss 0.3%
exploitation probability
0.3%top 84% of all CVEs
observed exploitation
nono source reports it
Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSRF attacks from occurring, therefore an attacker could abuse this vulnerability to create new customers. This issue has been patched in version 4.0.5.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Affected products
pimcore · customer-data-frameworkRelated CVEs — pimcore customer-data-framework
In the same product, most dangerous first.
CVE-2023-32075MEDIUMPimcore vulnerable to Business Logic Errors in Customer automation rulesEPSS 0.8%CVE-2024-21667MEDIUMPimcore Customer Data Framework Improper Access Control allows unprivileged user to access GDPR extractsEPSS 0.6%CVE-2024-21666MEDIUMPimcore Customer Data Framework Improper Access Control allows unprivileged user to access customers duplicates listEPSS 0.6%