{"id":"CVE-2023-42817","summary":"Cross-site Scripting (XSS) in pimcore admin-ui-classic-bundle translations","details":"Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user. The translations may be accessible by a user with comparatively lower overall access (as the translation permission cannot be scoped to certain “modules”) and a skilled attacker might be able to exploit the parsing of the translation string in the dialog box. This issue has been patched in commit `abd77392` which is included in release 1.1.2. Users are advised to update to version 1.1.2 or apply the patch manually.\n","aliases":["GHSA-m988-7375-7g2c"],"modified":"2026-08-12T03:51:38.954537927Z","published":"2023-09-25T18:57:33.735Z","database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/42xxx/CVE-2023-42817.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/42xxx/CVE-2023-42817.json"},{"type":"ADVISORY","url":"https://github.com/pimcore/admin-ui-classic-bundle/security/advisories/GHSA-m988-7375-7g2c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-42817"},{"type":"FIX","url":"https://github.com/pimcore/admin-ui-classic-bundle/commit/abd7739298f974319e3cac3fd4fcd7f995b63e4c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pimcore/admin-ui-classic-bundle","events":[{"introduced":"0"},{"fixed":"9ab8863e7046dfe14cd1c7d71becfac66f374446"},{"fixed":"abd7739298f974319e3cac3fd4fcd7f995b63e4c"}],"database_specific":{"cpe":"cpe:2.3:a:pimcore:admin_classic_bundle:*:*:*:*:*:pimcore:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.1.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.1.1","v1.1.0","v1.1.0-RC1","v1.0.0","v1.0.0-RC2","v1.0.0-RC1","v1.0.0-BETA1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-42817.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}