Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-0704: Cross-site Scripting (XSS) - Stored in pimcore

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

CVE
#xss#vulnerability#git

Description

Cross site scripting vulnerability in pimcore,pimcore field, it is fixed in this commit 832c34 , but still it is executing xss .Icon field in events and news

Proof of Concept

1 . Login to the demo account https://10.x-dev.pimcore.fun/admin/

  1. Go to settings -->data objects --> classes --> Events icon field --> add payload and click save

  2. Go to data objects tab which is located at the bottom, go to events folder and extend alert will trigger .

  3. payload = “><iMg SrC="x” oNeRRor="alert(1);">

Impact

This vulnerability is capable of stolen the user cookie

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907