Cross-site scripting in Pimcore admin-ui-classic-bundle - CVE-2023-37280
Published: July 11, 2023 / Updated: July 22, 2026
Pimcore admin-ui-classic-bundle
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary scripts in the victim's browser.
The vulnerability exists due to cross-site scripting in the /admin/login/2fa-setup endpoint when handling the error parameter. A remote attacker can send a specially crafted request to execute arbitrary scripts in the victim's browser.
Only admins who have not set up two-factor authentication are affected.