Cross-site Scripting (XSS) - Stored in pimcore/pimcore

Valid

Reported on

Dec 24th 2021


Description

The pimcore/pimcore package is an open source platform that provides PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce services. stored xss vulnerability occurs when you change the rule name in the admin dev page.

Proof of Concept

XSS POC : <img src=x onerror=alert(document.domain)>

1. Open the https://10.x-dev.pimcore.fun/admin/login?perspective=
2. After login, Go to "Online Shop" => "Pricing Rules"
3. Change the name of the rule to XSS POC
4. Refresh

Video : https://www.youtube.com/watch?v=7sTclCmH1rY

Impact

Through this vulnerability, an attacker is capable to execute malicious scripts.

We are processing your report and will contact the pimcore team within 24 hours. 5 months ago
Pocas modified the report
5 months ago
We have contacted a member of the pimcore team and are waiting to hear back 5 months ago
We have sent a follow up to the pimcore team. We will try again in 7 days. 5 months ago
Pocas
5 months ago

Researcher


When will the maintainer check this?

Pocas modified the report
5 months ago
We have sent a second follow up to the pimcore team. We will try again in 10 days. 5 months ago
Pocas
5 months ago

Researcher


Hey

We have sent a third and final follow up to the pimcore team. This report is now considered stale. 4 months ago
Bernhard Rusch validated this vulnerability 4 months ago
Pocas has been awarded the disclosure bounty
The fix bounty is now up for grabs
Bernhard Rusch confirmed that a fix has been merged on dfaf78 4 months ago
Bernhard Rusch has been awarded the fix bounty
to join this conversation