CVE-2022-0705

Description

The pimcore/pimcore package is an open source platform that provides PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce services. stored xss vulnerability occurs when you change the value of Abbreviation, Longname, Converter Service at “Settings” => “Data Objects” => “Quantity Value” in the pimcore service.


Proof of Concept

1
2
3
4
5
6
7
8
XSS POC : "><img src=x onerror=alert(document.domain)>

1. Open the https://10.x-dev.pimcore.fun/admin/login?perspective=
2. After login, Go to "Settings" => "Data Objects" => "Quantity Value"
3. Change the value of Abbreviation, Longname, Converter service to XSS PoC
4. Reflesh

Video : https://www.youtube.com/watch?v=c8waBKF5VAQ

Reporting Timeline

  • 2022-02-07 22h 16m : Reported this issue via the huntr
  • 2022-02-21 18h 12m : Validated this issue by Divesh Pahuja
  • 2022-02-21 18h 12m : Assigned a CVE-2022-0705

Reference