Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-0705: Cross-site Scripting (XSS) - Stored in pimcore

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

CVE
#xss#vulnerability#git

Description

The pimcore/pimcore package is an open source platform that provides PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce services. stored xss vulnerability occurs when you change the value of Abbreviation, Longname, Converter Service at “Settings” => “Data Objects” => “Quantity Value” in the pimcore service.

Proof of Concept

XSS POC : "><img src=x onerror=alert(document.domain)>

1. Open the https://10.x-dev.pimcore.fun/admin/login?perspective=
2. After login, Go to "Settings" => "Data Objects" => "Quantity Value"
3. Change the value of Abbreviation, Longname, Converter service to XSS PoC
4. Reflesh

Video : https://www.youtube.com/watch?v=c8waBKF5VAQ

Impact

Through this vulnerability, an attacker is capable to execute malicious scripts.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907