{"id":"GHSA-m988-7375-7g2c","summary":"pimcore/admin-ui-classic-bundle Cross-site Scripting vulnerability in Translations","details":"### Impact\nThe translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user.\n\nThe translations may be accessible by a user with comparatively lower overall access (as the translation permission cannot be scoped to certain “modules”) and a skilled attacker might be able to exploit the parsing of the translation string in the dialog box.\n\n### Patches\nhttps://github.com/pimcore/admin-ui-classic-bundle/commit/abd7739298f974319e3cac3fd4fcd7f995b63e4c.patch\n\n### Workarounds\nUpdate to version 1.1.2 or apply this patches manually\nhttps://github.com/pimcore/admin-ui-classic-bundle/commit/abd7739298f974319e3cac3fd4fcd7f995b63e4c.patch\n","aliases":["CVE-2023-42817"],"modified":"2023-11-08T05:26:19.919168Z","published":"2023-09-25T17:34:11Z","database_specific":{"nvd_published_at":"2023-09-25T19:15:10Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-09-25T17:34:11Z"},"references":[{"type":"WEB","url":"https://github.com/pimcore/admin-ui-classic-bundle/security/advisories/GHSA-m988-7375-7g2c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-42817"},{"type":"WEB","url":"https://github.com/pimcore/admin-ui-classic-bundle/commit/abd7739298f974319e3cac3fd4fcd7f995b63e4c"},{"type":"PACKAGE","url":"https://github.com/pimcore/admin-ui-classic-bundle"}],"affected":[{"package":{"name":"pimcore/admin-ui-classic-bundle","ecosystem":"Packagist","purl":"pkg:composer/pimcore/admin-ui-classic-bundle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.2"}]}],"versions":["v1.0.0","v1.0.0-BETA1","v1.0.0-RC1","v1.0.0-RC2","v1.0.1","v1.0.2","v1.0.3","v1.0.4","v1.0.5","v1.0.6","v1.1.0","v1.1.0-RC1","v1.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-m988-7375-7g2c/GHSA-m988-7375-7g2c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}