Cross-site Scripting (XSS) - Stored in pimcore/pimcore
Valid
Reported on
Feb 16th 2023
Description
- https://11.x-dev.pimcore.fun/admin/
- Go to Settings -> Thumbnails -> Video Thumbnails
- Click the button (Add Media Segment)
- Write : "><img src=x onerror=alert(document.domain)> and then click ok
Impact
excute script
We are processing your report and will contact the
pimcore
team within 24 hours.
a month ago
We have contacted a member of the
pimcore
team and are waiting to hear back
a month ago
hello they said me https://huntr.dev/bounties/ee86781c-3ca9-4dbc-8315-8ee243fb3b2b/ is duple with this report. please maintainer checks amazing haha
The researcher has received a minor penalty to their credibility for miscalculating the severity: -1
The researcher's credibility has increased: +7
The fix bounty has been dropped
This vulnerability has been assigned a CVE
to join this conversation