Cross-site Scripting (XSS) - Stored in pimcore/pimcore

Valid

Reported on

Feb 7th 2022


Description

The pimcore/pimcore package is an open source platform that provides PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce services. stored xss vulnerability occurs when you change the value of Abbreviation, Longname, Converter Service at "Settings" => "Data Objects" => "Quantity Value" in the pimcore service.

Proof of Concept

XSS POC : "><img src=x onerror=alert(document.domain)>

1. Open the https://10.x-dev.pimcore.fun/admin/login?perspective=
2. After login, Go to "Settings" => "Data Objects" => "Quantity Value"
3. Change the value of Abbreviation, Longname, Converter service to XSS PoC
4. Reflesh

Video : https://www.youtube.com/watch?v=c8waBKF5VAQ

Impact

Through this vulnerability, an attacker is capable to execute malicious scripts.

We are processing your report and will contact the pimcore team within 24 hours. a year ago
We have contacted a member of the pimcore team and are waiting to hear back a year ago
We have sent a follow up to the pimcore team. We will try again in 7 days. a year ago
Pocas
a year ago

Researcher


hey

We have sent a second follow up to the pimcore team. We will try again in 10 days. a year ago
Divesh Pahuja modified the report
a year ago
Divesh Pahuja validated this vulnerability a year ago
Pocas has been awarded the disclosure bounty
The fix bounty is now up for grabs
We have sent a fix follow up to the pimcore team. We will try again in 7 days. a year ago
We have sent a second fix follow up to the pimcore team. We will try again in 10 days. a year ago
Pocas
a year ago

Researcher


Hello :) when wiil you patch ?

Pocas
a year ago

Researcher


update?

Divesh Pahuja
a year ago

Maintainer


Hi @Pocas we are working on generic approach to fix XSS issues. The PR https://github.com/pimcore/pimcore/pull/11447 is already there and soon it will be merged. thanks!

Pocas
a year ago

Researcher


Thanks maintainer!

We have sent a third and final fix follow up to the pimcore team. This report is now considered stale. a year ago
Divesh Pahuja marked this as fixed in 10.4.0 with commit 6e0922 a year ago
Divesh Pahuja has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation