Cross-site Scripting (XSS) - Stored in pimcore/pimcore


Reported on

Jul 9th 2021

✍️ Description

pimcore is a Open Source Data & Experience Management Platform (PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce) this package is vulnerable for Stored XSS thru gender tag

🕵️‍♂️ Proof of Concept


💥 Impact

This vulnerability is capable of stored xss 📍 Location Gender.php#L21


2 years ago


Hey b1nslashsh, contacted with pimcore maintainers about this. Waiting to hear back!

Jamie Slome
2 years ago


@ziding - can we just check into this?

Abdul muhaimin modified the report
2 years ago
Bernhard Rusch validated this vulnerability 2 years ago
Abdul muhaimin has been awarded the disclosure bounty
The fix bounty is now up for grabs
Bernhard Rusch marked this as fixed with commit 9fd55a 2 years ago
Bernhard Rusch has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation