Cross-site Scripting (XSS) - Stored in pimcore/pimcore
Jan 18th 2022
stored xss vulnerability occurs when you change the value of Group at "Settings" => "Thumbnalis" => "Video Thumbnails" in the pimcore service.
Proof of Concept
XSS POC : "><img src=x onerror=alert(document.domain)> 1. Open the https://10.x-dev.pimcore.fun/admin/login?perspective= 2. After login, Go to "Settings" => "Thumbnalis" => "Video Thumbnails" 3. Change the value of Group to XSS PoC 4. Reflesh
Through this vulnerability, an attacker is capable to execute malicious scripts.
Divesh Pahuja validated this vulnerability a year ago
TroubleMaker has been awarded the disclosure bounty
The fix bounty is now up for grabs
Divesh Pahuja marked this as fixed in 10.2.9 with commit b43222 a year ago
This vulnerability will not receive a CVE
to join this conversation