CVE-2018-14057: Pimcore
High severity, CVSS 8.8. EPSS: 3.3% chance of exploitation in the next 30 days.
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function.
Affected products
- Pimcore Pimcore: before 5.3.0 (fixed in 5.3.0)
Published 2018-08-17. Last modified 2026-06-17.