High severity7.8NVD Advisory· Published May 10, 2023· Updated Jun 17, 2026
CVE-2023-2629
CVE-2023-2629
Description
Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pimcore/customer-management-framework-bundlePackagist | < 3.3.9 | 3.3.9 |
Affected products
3- cpe:2.3:a:pimcore:customer_management_framework:*:*:*:*:*:pimcore:*:*Range: <3.3.9
- pimcore/pimcore/customer-data-frameworkv5Range: unspecified
Patches
Vulnerability mechanics
References
5- github.com/pimcore/customer-data-framework/commit/4e0105c3a78d20686a0c010faef27d2297b98803nvdPatchWEB
- huntr.dev/bounties/821ff465-4754-42d1-9376-813c17f16a01nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-mq3x-qgwx-3rfwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-2629ghsaADVISORY
- github.com/pimcore/customer-data-framework/security/advisories/GHSA-mq3x-qgwx-3rfwghsaWEB
News mentions
0No linked articles in our index yet.