Cross-site Scripting (XSS) - Stored in pimcore/pimcore
Valid
Reported on
Dec 24th 2021
Description
The pimcore/pimcore package is an open source platform that provides PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce services. stored xss vulnerability occurs when you change the rule name in the admin dev page.
Proof of Concept
XSS POC : <img src=x onerror=alert(document.domain)>
1. Open the https://10.x-dev.pimcore.fun/admin/login?perspective=
2. After login, Go to "Online Shop" => "Pricing Rules"
3. Change the name of the rule to XSS POC
4. Refresh
Video : https://www.youtube.com/watch?v=7sTclCmH1rY
Impact
Through this vulnerability, an attacker is capable to execute malicious scripts.
We are processing your report and will contact the
pimcore
team within 24 hours.
a year ago
Pocas modified the report
a year ago
We have contacted a member of the
pimcore
team and are waiting to hear back
a year ago
We have sent a
follow up to the
pimcore
team.
We will try again in 7 days.
a year ago
Pocas modified the report
a year ago
We have sent a
second
follow up to the
pimcore
team.
We will try again in 10 days.
a year ago
We have sent a
third and final
follow up to the
pimcore
team.
This report is now considered stale.
a year ago
to join this conversation