Cross-site Scripting (XSS) - Stored in pimcore/customer-data-framework

Valid

Reported on

Jan 25th 2022


Description

stored xss vulnerability occurs when you change the value of Description at "Customer Management Framework" => "Customer automation rules" => "New Customers" => "Description" in the pimcore service.

Proof of Concept

XSS POC : <img src=x onerror=alert(document.domain)>

1. Open the https://10.x-dev.pimcore.fun/admin/
2. After login, Go to "Customer Management Framework" => "Customer automation rules" => "New Customers" => "Description"
3. Change the value of Group to XSS PoC

Impact

Through this vulnerability, an attacker is capable to execute malicious scripts.

We are processing your report and will contact the pimcore/customer-data-framework team within 24 hours. a year ago
We have contacted a member of the pimcore/customer-data-framework team and are waiting to hear back a year ago
We have sent a follow up to the pimcore/customer-data-framework team. We will try again in 7 days. a year ago
Divesh Pahuja validated this vulnerability a year ago
TroubleMaker has been awarded the disclosure bounty
The fix bounty is now up for grabs
Divesh Pahuja marked this as fixed in 3.2.6 with commit ff7684 a year ago
Divesh Pahuja has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation