cross site scripting in pimcore/pimcore
Valid
Reported on
Mar 10th 2023
Pimcore is vulnerable to Cross site scripting vulnerability in classes module.
Impact
Step to reproduce:
- Navigate to setting > Data Objects > Classes.
- Select any classes and add Composite indices.
- Add Xss payload on it.
Payload: "><img src=x onerror=alert(document.cookie)>
We are processing your report and will contact the
pimcore
team within 24 hours.
2 months ago
We have contacted a member of the
pimcore
team and are waiting to hear back
2 months ago
The researcher has received a minor penalty to their credibility for miscalculating the severity: -1
The researcher's credibility has increased: +7
The fix bounty has been dropped
This vulnerability has been assigned a CVE
to join this conversation