Cross-site Scripting (XSS) - Stored in pimcore/data-hub


Reported on

Jan 25th 2022


The pimcore/pimcore package is an open source platform that provides PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce services. stored xss vulnerability occurs when you change the value of Group at "Datahub" in the pimcore service.

Proof of Concept

XSS POC : "><img src=x onerror=alert(document.domain)>

1. Open the
2. After login, Go to "Datahub"
3. Change the value of Group to XSS PoC
4. Reflesh

Video :


Through this vulnerability, an attacker is capable to execute malicious scripts.

We are processing your report and will contact the pimcore/data-hub team within 24 hours. a year ago
Divesh Pahuja validated this vulnerability a year ago
Pocas has been awarded the disclosure bounty
The fix bounty is now up for grabs
Divesh Pahuja marked this as fixed in 1.2.1 with commit 6a85b7 a year ago
Divesh Pahuja has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation