Cross-site Scripting (XSS) - Stored in pimcore/pimcore


Reported on

Aug 27th 2021

✍️ Description

pimcore is a Open Source Data & Experience Management Platform (PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce) this package is vulnerable for Stored XSS thru adding customer

🕵️‍♂️ Proof of Concept


💥 Impact

This vulnerability is capable of XSS

We have contacted a member of the pimcore team and are waiting to hear back a year ago
Divesh Pahuja validated this vulnerability a year ago
Abdul muhaimin has been awarded the disclosure bounty
The fix bounty is now up for grabs
Divesh Pahuja confirmed that a fix has been merged on 6321e8 a year ago
The fix bounty has been dropped
to join this conversation