CVE-2023-32075
CVE-2023-32075 is a medium-severity vulnerability in Pimcore Customer Management Framework with a CVSS 3.x base score of 4.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-20.
Key facts
- Severity: Medium (CVSS 3.x base score 4.3)
- EPSS exploit prediction: 1% (53rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-20
- Affected product: Pimcore Customer Management Framework
- Published:
- Last modified:
Description
The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management. In `pimcore/customer-management-framework-bundle` prior to version 3.3.9, business logic errors are possible in the `Conditions` tab since the counter can be a negative number. This vulnerability is capable of the unlogic in the counter value in the Conditions tab. Users should update to version 3.3.9 to receive a patch or, as a workaround, or apply the patch manually.
Frequently asked questions
- What is CVE-2023-32075?
- The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management. In `pimcore/customer-management-framework-bundle` prior to version 3.3.9, business logic errors are possible in the `Conditions` tab since the counter can be a negative number. This vulnerability is capable of the unlogic in the counter value in the Conditions tab. Users should update to version 3.3.9 to receive a patch or, as a workaround, or apply the patch manually.
- How severe is CVE-2023-32075?
- CVE-2023-32075 has a CVSS 3.x base score of 4.3, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2023-32075 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (53rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-32075?
- CVE-2023-32075 affects Pimcore Customer Management Framework. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-32075?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2023-32075 published?
- CVE-2023-32075 was published on 2023-05-11 and last updated on 2026-06-17.
References
- https://github.com/pimcore/customer-data-framework/commit/e3f333391582d9309115e6b94e875367d0ea7163.patch
- https://github.com/pimcore/customer-data-framework/releases/tag/v3.3.9
- https://github.com/pimcore/customer-data-framework/security/advisories/GHSA-x99j-r8vv-gwwj
- https://huntr.dev/bounties/cecd7800-a996-4f3a-8689-e1c2a1e0248a/
Affected products (1)
- cpe:2.3:a:pimcore:customer_management_framework:*:*:*:*:*:pimcore:*:*
More vulnerabilities in Pimcore Customer Management Framework
- CVE-2023-2629 — High (CVSS 7.8): Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to…
- CVE-2023-2756 — High (CVSS 7.2): SQL Injection in GitHub repository pimcore/customer-data-framework prior to 3.3.10.
- CVE-2024-21667 — Medium (CVSS 6.5): pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An…
- CVE-2024-21666 — Medium (CVSS 6.5): The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation,…
- CVE-2023-3574 — Medium (CVSS 6.5): Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1.
- CVE-2021-31867 — Medium (CVSS 6.5): Pimcore Customer Data Framework version 3.0.0 and earlier suffers from a Boolean-based blind SQL injection issue in the…
All CVEs affecting Pimcore Customer Management Framework →
Other CWE-20 (Improper Input Validation) vulnerabilities
- CVE-2026-48056 — Critical (CVSS 10.0): Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0…
- CVE-2026-33267 — Critical (CVSS 10.0): Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0…
- CVE-2026-47668 — Critical (CVSS 10.0): DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST…
- CVE-2026-16117 — Critical (CVSS 10.0): Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix…
- CVE-2026-48316 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could…
- CVE-2026-48281 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could…
Browse all CWE-20 (Improper Input Validation) vulnerabilities →