Cross-site Scripting (XSS) - Stored in pimcore/pimcore

Valid

Reported on

Jul 9th 2021


✍️ Description

pimcore is a Open Source Data & Experience Management Platform (PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce) this package is vulnerable for Stored XSS thru gender tag

🕵️‍♂️ Proof of Concept

poc

💥 Impact

This vulnerability is capable of stored xss 📍 Location Gender.php#L21

Ziding Zhang
5 months ago

Admin


Hey b1nslashsh, contacted with pimcore maintainers about this. Waiting to hear back!

Jamie Slome
5 months ago

Admin


@ziding - can we just check into this?

Abdul muhaimin modified their report
3 months ago
Bernhard Rusch validated this vulnerability 3 months ago
Abdul muhaimin has been awarded the disclosure bounty
The fix bounty is now up for grabs
Bernhard Rusch confirmed that a fix has been merged on 9fd55a 3 months ago
Bernhard Rusch has been awarded the fix bounty