Cross-site Scripting (XSS) - Stored in pimcore/pimcore
Reported on
Jan 19th 2022
Description
Pimcore settings module is vulnerable to stored cross site scripting
Proof of Concept
1 . Login to dev demo account. https://10.x-dev.pimcore.fun/
2 . Goto settings -->data objects -->Add a new class --> add payload in icon field
3 . Click save and close and open that class alert will trigger
payload "><iMg SrC="x" oNeRRor="alert(document.domain);">
Impact
This vulnerability is capable of stolen the user cookie