Skip to content

Commit 2e00592

Browse files
Move new vulnerability to vulnerabilities/AIKIDO-2025-10427.json and reset new.json template
1 parent 3ba9c07 commit 2e00592

File tree

2 files changed

+38
-21
lines changed

2 files changed

+38
-21
lines changed

input/new.json

Lines changed: 12 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -1,24 +1,15 @@
11
{
2-
"package_name": "pimcore/admin-ui-classic-bundle",
3-
"patch_versions": [
4-
"2.1.0"
5-
],
6-
"vulnerable_ranges": [
7-
[
8-
"2.0.0",
9-
"2.0.2"
10-
]
11-
],
12-
"cwe": [
13-
"CWE-79"
14-
],
15-
"tldr": "Affected versions of this package are vulnerable to stored Cross-Site Scripting (XSS) due to improper HTML encoding of user-controlled parameters in the email log interface. Attackers can exploit this vulnerability by injecting malicious HTML or JavaScript into email template variables. When administrators view the email log, the malicious payload executes in their session, which can lead to session hijacking, data theft, or compromise of the admin account.",
16-
"doest_this_affect_me": "You are affected if you are using a version that falls within the vulnerable range.",
17-
"how_to_fix": "Upgrade the `pimcore/admin-ui-classic-bundle` library to the patch version.",
18-
"vulnerable_to": "Cross-Site Scripting (XSS)",
2+
"package_name": "",
3+
"patch_versions": [],
4+
"vulnerable_ranges": [],
5+
"cwe": [],
6+
"tldr": "",
7+
"doest_this_affect_me": "",
8+
"how_to_fix": "",
9+
"vulnerable_to": "",
1910
"related_cve_id": "",
20-
"language": "PHP",
21-
"severity_class": "HIGH",
22-
"aikido_score": 81,
23-
"changelog": "https://github.com/pimcore/admin-ui-classic-bundle/releases/tag/v2.1.0"
11+
"language": "",
12+
"severity_class": "",
13+
"aikido_score": 0,
14+
"changelog": ""
2415
}
Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
{
2+
"package_name": "pimcore/admin-ui-classic-bundle",
3+
"patch_versions": [
4+
"2.1.0"
5+
],
6+
"vulnerable_ranges": [
7+
[
8+
"2.0.0",
9+
"2.0.2"
10+
]
11+
],
12+
"cwe": [
13+
"CWE-79"
14+
],
15+
"tldr": "Affected versions of this package are vulnerable to stored Cross-Site Scripting (XSS) due to improper HTML encoding of user-controlled parameters in the email log interface. Attackers can exploit this vulnerability by injecting malicious HTML or JavaScript into email template variables. When administrators view the email log, the malicious payload executes in their session, which can lead to session hijacking, data theft, or compromise of the admin account.",
16+
"doest_this_affect_me": "You are affected if you are using a version that falls within the vulnerable range.",
17+
"how_to_fix": "Upgrade the `pimcore/admin-ui-classic-bundle` library to the patch version.",
18+
"vulnerable_to": "Cross-Site Scripting (XSS)",
19+
"related_cve_id": "",
20+
"language": "PHP",
21+
"severity_class": "HIGH",
22+
"aikido_score": 81,
23+
"changelog": "https://github.com/pimcore/admin-ui-classic-bundle/releases/tag/v2.1.0",
24+
"last_modified": "2025-07-01",
25+
"published": "2025-07-01"
26+
}

0 commit comments

Comments
 (0)