Cross-site Scripting (XSS) - Stored in pimcore/pimcore

Valid

Reported on

Jan 19th 2022


Description

Pimcore settings module is vulnerable to stored cross site scripting

Proof of Concept

1 . Login to dev demo account. https://10.x-dev.pimcore.fun/

2 . Goto settings -->data objects -->Add a new class --> add payload in icon field

3 . Click save and close and open that class alert will trigger

payload "><iMg SrC="x" oNeRRor="alert(document.domain);">

Impact

This vulnerability is capable of stolen the user cookie

We are processing your report and will contact the pimcore team within 24 hours. 4 months ago
Asura-N modified the report
4 months ago
We have contacted a member of the pimcore team and are waiting to hear back 4 months ago
We have sent a follow up to the pimcore team. We will try again in 7 days. 4 months ago
Divesh Pahuja validated this vulnerability 4 months ago
Asura-N has been awarded the disclosure bounty
The fix bounty is now up for grabs
JiaJia Ji confirmed that a fix has been merged on 832c34 4 months ago
JiaJia Ji has been awarded the fix bounty
to join this conversation