Cross-site Scripting (XSS) - Stored in pimcore/pimcore

Valid

Reported on

Aug 27th 2021


✍️ Description

pimcore is a Open Source Data & Experience Management Platform (PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce) this package is vulnerable for Stored XSS thru SEO menu

🕵️‍♂️ Proof of Concept

💥 Impact

This vulnerability is capable of...

We have contacted a member of the pimcore team and are waiting to hear back 2 years ago
Bernhard Rusch validated this vulnerability 2 years ago
Abdul muhaimin has been awarded the disclosure bounty
The fix bounty is now up for grabs
Bernhard Rusch marked this as fixed with commit aadd37 2 years ago
Bernhard Rusch has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation