Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.19.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://huntr.dev/bounties/31d97442-3f87-439f-83f0-1c7862ef0c7c | third party advisory exploit |
https://github.com/pimcore/pimcore/commit/82cca7f4a7560b160336cce2610481098ca52c18 | patch |