Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in Pimcore admin-ui-classic-bundle - CVE-2023-46722
Published: October 31, 2023 / Updated: July 22, 2026
Pimcore admin-ui-classic-bundle
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a user's browser.
The vulnerability exists due to cross-site scripting in PDF previews when rendering an uploaded PDF file. A remote user can upload a PDF containing a script payload to execute arbitrary script in a user's browser.
The issue can lead to cookie theft, unauthorized access via a stolen cookie, or redirection to malicious sites. User interaction is required to view the PDF preview.