Headline
CVE-2022-0705: Cross-site Scripting (XSS) - Stored in pimcore
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
Description
The pimcore/pimcore package is an open source platform that provides PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce services. stored xss vulnerability occurs when you change the value of Abbreviation, Longname, Converter Service at “Settings” => “Data Objects” => “Quantity Value” in the pimcore service.
Proof of Concept
XSS POC : "><img src=x onerror=alert(document.domain)>
1. Open the https://10.x-dev.pimcore.fun/admin/login?perspective=
2. After login, Go to "Settings" => "Data Objects" => "Quantity Value"
3. Change the value of Abbreviation, Longname, Converter service to XSS PoC
4. Reflesh
Video : https://www.youtube.com/watch?v=c8waBKF5VAQ
Impact
Through this vulnerability, an attacker is capable to execute malicious scripts.