Cross-site Scripting (XSS) - Stored in pimcore/pimcore
Valid
Reported on
Jan 19th 2022
Description
Pimcore settings module is vulnerable to stored cross site scripting
Proof of Concept
1 . Login to dev demo account. https://10.x-dev.pimcore.fun/
2 . Goto settings -->data objects -->Add a new class --> add payload in icon field
3 . Click save and close and open that class alert will trigger
payload "><iMg SrC="x" oNeRRor="alert(document.domain);">
Impact
This vulnerability is capable of stolen the user cookie
We are processing your report and will contact the
pimcore
team within 24 hours.
a year ago
Asura-N modified the report
a year ago
We have contacted a member of the
pimcore
team and are waiting to hear back
a year ago
We have sent a
follow up to the
pimcore
team.
We will try again in 7 days.
a year ago
to join this conversation