CVE-2023-37280: Pimcore Admin Classic Bundle

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Pimcore Admin Classic Bundle provides a Backend UI for Pimcore based on the ExtJS framework. An admin who has not setup two factor authentication before is vulnerable for this attack, without need for any form of privilege, causing the application to execute arbitrary scripts/HTML content. This vulnerability has been patched in version 1.0.3.

Affected products

  • Pimcore Admin Classic Bundle: before 1.0.3 (fixed in 1.0.3)

Published 2023-07-11. Last modified 2026-06-17.