Cross-site Scripting (XSS) - Stored in pimcore/pimcore
Valid
Reported on
Jan 17th 2022
Description
The pimcore/pimcore package is an open source platform that provides PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce services. stored xss vulnerability occurs when you add media query at "Settings" => "Thumbnails" => "Video Thumbnails" in the pimcore service.
Proof of Concept
XSS POC : "><img src=x onerror=alert(document.domain)>
1. Open the https://10.x-dev.pimcore.fun/admin/login?perspective=
2. After login, Go to "Settings" => "Thumbnails" => "Video Thumbnails"
3. Click the Any Video
4. Click the Add Media Segment Button
5. Enter the XSS POC and Click the OK
6. Add Transformations!!
7. Reflesh
Video : https://youtu.be/OZQqIugDyBE
Impact
Through this vulnerability, an attacker is capable to execute malicious scripts.
We are processing your report and will contact the
pimcore
team within 24 hours.
a year ago
Pocas modified the report
a year ago
to join this conversation