Medium severity5.4NVD Advisory· Published Aug 3, 2023· Updated Jun 17, 2026
CVE-2023-4145
CVE-2023-4145
Description
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pimcore/customer-management-framework-bundlePackagist | < 3.4.2 | 3.4.2 |
Affected products
3- cpe:2.3:a:pimcore:customer_management_framework:*:*:*:*:*:pimcore:*:*Range: <3.4.2
- pimcore/pimcore/customer-data-frameworkv5Range: unspecified
Patches
Vulnerability mechanics
References
6- github.com/pimcore/customer-data-framework/commit/72f45dd537a706954e7a71c99fbe318640e846a2nvdPatchWEB
- huntr.dev/bounties/ce852777-2994-40b4-bb4e-c4d10023eeb0nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-735f-w79p-282xghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-4145ghsaADVISORY
- github.com/pimcore/customer-data-framework/commit/72f45dd537a706954e7a71c99fbe318640e846a2.patchghsaWEB
- github.com/pimcore/customer-data-framework/security/advisories/GHSA-735f-w79p-282xghsaWEB
News mentions
0No linked articles in our index yet.