PT-2021-22428 · Pimcore · Pimcore
Brusch
·
Published
2021-09-01
·
Updated
2021-09-09
·
CVE-2021-39170
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pimcore versions prior to 10.1.2
Description
Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets.
Recommendations
For versions prior to 10.1.2, update to version 10.1.2 to resolve the issue.
As a temporary workaround, users may apply the patch manually.
Exploit
Fix
Improper Encoding or Escaping of Output
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pimcore