Cross-site Scripting (XSS) - Stored in pimcore/customer-data-framework
Valid
Reported on
Jan 25th 2022
Description
stored xss vulnerability occurs when you change the value of Description at "Customer Management Framework" => "Customer automation rules" => "New Customers" => "Description" in the pimcore service.
Proof of Concept
XSS POC : <img src=x onerror=alert(document.domain)>
1. Open the https://10.x-dev.pimcore.fun/admin/
2. After login, Go to "Customer Management Framework" => "Customer automation rules" => "New Customers" => "Description"
3. Change the value of Group to XSS PoC
Impact
Through this vulnerability, an attacker is capable to execute malicious scripts.
We are processing your report and will contact the
pimcore/customer-data-framework
team within 24 hours.
a year ago
We have contacted a member of the
pimcore/customer-data-framework
team and are waiting to hear back
a year ago
We have sent a
follow up to the
pimcore/customer-data-framework
team.
We will try again in 7 days.
a year ago
to join this conversation